Key Takeaways
- In 2023, over 10 billion passwords were exposed in data breaches worldwide according to cybersecurity reports
- The 2023 Verizon Data Breach Investigations Report (DBIR) found that 81% of breaches involved weak, default, or stolen credentials
- RockYou2021 leak contained 8.4 billion unique passwords, the largest compilation ever
- "123456" was the most common password in the 2023 NordPass report, used by millions across leaks
- "123456789" ranked second in commonality, appearing in over 7.7 million leaked passwords per NordPass 2023
- "guest" is the 11th most common password, found in 1.2 million instances in breaches
- 59% of users reuse the exact same password across multiple accounts per 2023 Google survey
- Keeper Security 2023 report: 69% of people reuse passwords on work and personal accounts
- NordPass 2023: 82% of users have reused passwords, leading to credential stuffing attacks
- A 12-character password with uppercase, lowercase, numbers, symbols takes 34 years to crack with modern GPU
- 8-character lowercase-only password cracks in 2.5 hours on single GPU per Hive Systems 2023
- Passwords under 8 characters represent 20% of all leaked but crack 100% faster
- 2FA blocks 99.9% of automated attacks but only 30% adoption, Google 2023
- MFA reduces breach risk by 99% per Microsoft 2023 study on Azure AD
- 2023 Okta report: 37% of attacks bypassed legacy MFA like SMS
Weak and reused passwords are causing billions of accounts to be breached.
Common Weak Passwords
Common Weak Passwords Interpretation
Multi-Factor Authentication and Alternatives
Multi-Factor Authentication and Alternatives Interpretation
Password Breaches and Leaks
Password Breaches and Leaks Interpretation
Password Reuse Statistics
Password Reuse Statistics Interpretation
Password Strength Metrics
Password Strength Metrics Interpretation
Sources & References
- Reference 1HAVEIBEENPWNEDhaveibeenpwned.comVisit source
- Reference 2VERIZONverizon.comVisit source
- Reference 3BLEEPINGCOMPUTERbleepingcomputer.comVisit source
- Reference 4CYBERNEWScybernews.comVisit source
- Reference 5BBCbbc.comVisit source
- Reference 6TROYHUNTtroyhunt.comVisit source
- Reference 7ZDNETzdnet.comVisit source
- Reference 8FTCftc.govVisit source
- Reference 9REUTERSreuters.comVisit source
- Reference 10NEWSnews.marriott.comVisit source
- Reference 11CAPITALONEcapitalone.comVisit source
- Reference 12CORPORATEcorporate.homedepot.comVisit source
- Reference 13SONYsony.comVisit source
- Reference 14CORPORATEcorporate.target.comVisit source
- Reference 15ANTHEManthem.comVisit source
- Reference 16CANVAcanva.comVisit source
- Reference 17BUSINESSINSIDERbusinessinsider.comVisit source
- Reference 18BLOGblog.trello.comVisit source
- Reference 19INFOSECURITY-MAGAZINEinfosecurity-magazine.comVisit source
- Reference 20NORDPASSnordpass.comVisit source
- Reference 21SPECTRUMspectrum.ieee.orgVisit source
- Reference 22KASPERSKYkaspersky.comVisit source
- Reference 23GITHUBgithub.comVisit source
- Reference 24KEEPERSECURITYkeepersecurity.comVisit source
- Reference 25SPICEWORKSspiceworks.comVisit source
- Reference 26BLOGblog.googleVisit source
- Reference 27BLOGblog.lastpass.comVisit source
- Reference 28SPECOPSSOFTspecopssoft.comVisit source
- Reference 29PASSWORDMANAGERpasswordmanager.comVisit source
- Reference 30TEAMPASSWORDteampassword.comVisit source
- Reference 31BLOGblog.dashlane.comVisit source
- Reference 32CYBERSECURITYVENTUREScybersecurityventures.comVisit source
- Reference 33BITWARDENbitwarden.comVisit source
- Reference 34PROOFPOINTproofpoint.comVisit source
- Reference 351PASSWORD1password.comVisit source
- Reference 36AURAaura.comVisit source
- Reference 37SPYCLOUDspycloud.comVisit source
- Reference 38JUMPCLOUDjumpcloud.comVisit source
- Reference 39PONEMONponemon.orgVisit source
- Reference 40LASTPASSlastpass.comVisit source
- Reference 41NVLPUBSnvlpubs.nist.govVisit source
- Reference 42HIVE-SYSTEMShive-systems.comVisit source
- Reference 43PAGESpages.nist.govVisit source
- Reference 44XKCDxkcd.comVisit source
- Reference 45HASHCAThashcat.netVisit source
- Reference 46ZXCVBNzxcvbn.pm.davidwong.frVisit source
- Reference 47WORLDworld.std.comVisit source
- Reference 48LANDINGlanding.google.comVisit source
- Reference 49MICROSOFTmicrosoft.comVisit source
- Reference 50OKTAokta.comVisit source
- Reference 51SECURITYsecurity.googleblog.comVisit source
- Reference 52YUBICOyubico.comVisit source
- Reference 53DUOduo.comVisit source
- Reference 54TECHCOMMUNITYtechcommunity.microsoft.comVisit source
- Reference 55CHROMESTATUSchromestatus.comVisit source
- Reference 56FIDOALLIANCEfidoalliance.orgVisit source
- Reference 57SECURITYsecurity.apple.comVisit source
- Reference 58GITHUBgithub.blogVisit source
- Reference 59FORRESTERforrester.comVisit source






