Key Takeaways
- 2019: Average cost per compromised record in breaches involving credentials was $150, reflecting downstream account takeover due to reuse
- 2023: $1.98 million was the average cost of breaches involving stolen credentials (category-specific average)
- 2021: Identity-related incidents cost organizations an average of $15.5 million annually in large enterprises (including account takeover impacts)
- 2020: 80% of breaches involved human error, where credential compromise and password reuse are recurring contributors
- 2018: 45% of people used the same password across multiple sites at least sometimes
- 2021: 49% of users reused passwords across multiple websites, per analysis of large-scale credential leak patterns
- The leaked-password reuse rate across multiple datasets averaged 40% in a 2021 academic analysis of credential leaks (unique password adoption remained low across sites), per the paper’s empirical results
- 2016: Using password managers reduced password reuse by 40% in an intervention study (measured as unique password adoption)
- 2018: Rate limiting and bot detection blocked 88% of credential-stuffing attempts in a production deployment study
- 2022: 91% of organizations reported they use blocklists or allowlists for known bad credential sources, reducing password reuse attack success
- 2021: 479 million account records with credentials were reported in a major breach corpus used in password security analyses
- 76% of organizations reported they have experienced account takeovers in the last 12 months, according to the 2023 “Fraud & Security” survey by FICO (identity-related fraud impacts)
- Credential stuffing ranks among the top 5 web bot attack categories in 2024, with “credential stuffing” showing a measured share of 18% in observed bot traffic, per Distil Networks’ 2024 bot report
- 76% of enterprises reported using risk-based authentication to detect suspicious sign-ins in 2024, per the 2024 “Digital Trust” survey by Thales
Password reuse fuels costly breaches, and stronger controls like password managers and monitoring cut account takeovers.
Related reading
01 · Category
Cost Analysis10 stats
Cost Analysis Interpretation
02 · Category
Breach Impact1 stats
Breach Impact Interpretation
03 · Category
User Behavior8 stats
User Behavior Interpretation
04 · Category
Mitigation & Metrics3 stats
Mitigation & Metrics Interpretation
More related reading
05 · Category
Threat Landscape1 stats
Threat Landscape Interpretation
06 · Category
User Adoption1 stats
User Adoption Interpretation
07 · Category
Attack Prevalence1 stats
Attack Prevalence Interpretation
08 · Category
Detection & Mitigation1 stats
Detection & Mitigation Interpretation
Cite This Report
This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.
Marie Larsen. (2026, February 13). Password Reuse Statistics. Gitnux. https://gitnux.org/password-reuse-statistics
Marie Larsen. "Password Reuse Statistics." Gitnux, 13 Feb 2026, https://gitnux.org/password-reuse-statistics.
Marie Larsen. 2026. "Password Reuse Statistics." Gitnux. https://gitnux.org/password-reuse-statistics.
Sources & references
26 datasets cited across this report · attribution is report-level
+2 additional datasets cited (not shown individually)

