Passwords are the most-studied bad habit in computing. Every year, breach investigators, password-manager vendors and standards bodies publish mountains of data about how we create, reuse, lose and leak our credentials. And every year, the numbers tell the same uncomfortable story with fresh decimal points.

We've gathered more than 50 of the most telling statistics into one place, organized by theme, with the source named for each. Where a figure moves year to year, we cite the study and its reporting period rather than inventing precision.

Bookmark this page for your next security talk, staff-training deck or "why you should stop using your dog's name" argument.

The big picture: credentials, breaches and cost

Quick summary: attackers don't break in - They log in.

  1. Stolen credentials have appeared in roughly a third of all breaches tracked over the past decade, per Verizon's Data Breach Investigations Report (DBIR). That makes them the single most common way in.
  2. The classic headline still holds up. Verizon's 2017 DBIR found 81% of hacking-related breaches leveraged stolen or weak passwords.
  3. The 2024 DBIR found 68% of breaches involved the human element - Phishing, stolen credentials, errors and social engineering.
  4. Roughly eight in ten basic web application attacks involve stolen credentials, according to DBIR analyses. Attackers overwhelmingly log in rather than hack in.
  5. IBM's Cost of a Data Breach report put the global average breach cost at $4.88 million in 2024. That was the highest figure it had recorded to that point.
  6. The United States is consistently the most expensive country for breaches in IBM's data, with averages north of $9 million.
  7. Breaches that start with stolen credentials are among the slowest to catch. IBM's data puts identification and containment at close to 10 months on average.
  8. Microsoft reported blocking around 7,000 password attacks per second in 2024. That's up from roughly 4,000 per second the year before, and under 1,000 in 2022.
Breaches involving the human element (DBIR 2024)
68%
Hacking breaches via weak/stolen passwords (DBIR 2017)
81%

What our passwords actually look like

  1. "123456" has topped NordPass's annual most-common-password ranking in most years the study has run. It cracks in under one second.
  2. The rest of the perennial top five barely changes: "123456789", "12345678", "password" and "qwerty" variants shuffle positions year after year.
  3. "123456" alone appears millions of times in the breach corpora NordPass analyzes. That's one string shared by a small country's worth of accounts.
  4. NordPass found that 78% of the world's most common passwords can be cracked in less than a second.
  5. On device and admin-panel lists, "admin" - Often the factory default nobody changed - Routinely ranks number one.
  6. A Google/Harris Poll found 59% of US adults have used a name or birthday in a password. That's exactly the personal data that's easiest to look up.
  7. The same poll found about 24% have used some variant of "password", "123456" or "qwerty".
  8. Hive Systems' widely cited crack-time tables show an 8-character lowercase password falling to GPU hardware almost instantly under fast hashes. A random 16-character password, by contrast, holds out for billions of years.
  9. Penetration testers report that seasonal patterns like "Summer2026!" remain among the first guesses in password-spraying engagements. They satisfy complexity rules while staying utterly predictable.

Why do these passwords fail? And what do the leaked lists reveal about how we think? The full anatomy is in our companion piece on the most common passwords.

Rank Password (perennial NordPass top 5) Time to crack (NordPass estimate)
1 123456 Under 1 second
2 123456789 Under 1 second
3 12345678 Under 1 second
4 password Under 1 second
5 qwerty Under 1 second

Reuse, memory and the limits of the human brain

  1. NordPass research estimates the average person manages about 168 personal passwords.
  2. Add work accounts and the total climbs past 250 credentials per person.
  3. Gartner has long estimated that password resets eat a substantial share of IT help-desk call volume. Figures of 20–50% are commonly cited.
  4. In LastPass's Psychology of Passwords research, 91% of respondents said they know reusing passwords is a risk.
  5. Roughly six in ten admitted doing it anyway. That's the gap between knowing and doing, quantified.
  6. The Google/Harris Poll found 52% of people reuse the same password across multiple accounts. It found 13% reuse a single password everywhere.
  7. It also found 43% of US adults have shared a password with someone else.
  8. Security.org's annual surveys put password-manager use at roughly one in three Americans. That share is rising, but still a minority.
  9. Vendor surveys (Bitwarden's annual World Password Day study among them) consistently find that memory and handwritten notes remain the most common password-management "systems."
Know password reuse is risky (LastPass)
91%
Reuse passwords across accounts anyway (Google/Harris)
52%
Americans using a password manager (Security.org)
~36%

The whole password crisis in one sentence: we each hold about 168 keys, our brains can memorize maybe a dozen, and attackers have already read billions of the spares we left under the doormat.

Breaches by the numbers

  1. Have I Been Pwned is the breach-notification service run by Troy Hunt. It indexes more than 14 billion breached accounts.
  2. Its Pwned Passwords service lets sites screen sign-ups against known-leaked passwords. It contains close to a billion unique real-world passwords and serves billions of lookups a month.
  3. Collection #1 (2019) packed 773 million unique email addresses into a single freely traded dump.
  4. RockYou2024 stitched together roughly 10 billion unique passwords into one text file. It's the largest compilation ever published.
  5. Its namesake, the original 2009 RockYou breach, exposed 32 million plaintext passwords. It became the standard cracking dictionary that attackers still start from today.
  6. The largest single breach on record remains Yahoo: all 3 billion accounts, breached in 2013 and fully disclosed in 2017.
  7. The 2021 "COMB" compilation circulated over 3 billion email-password pairs. Old breaches never die - They get re-bundled.

Attacks in motion: phishing and credential stuffing

  1. Phishing is perennially the most-reported cybercrime to the FBI's Internet Crime Complaint Center. It drew close to 300,000 complaints in 2023 alone.
  2. Total cybercrime losses reported to the FBI hit $12.5 billion in 2023 and rose again to $16.6 billion in 2024.
  3. Verizon's 2024 DBIR measured the median time to click a phishing link at just 21 seconds after opening the email. Data was entered in under a minute.
  4. The Anti-Phishing Working Group observed around five million phishing attacks in 2023, its worst year on record at the time.
  5. The large majority of phishing sites now use valid HTTPS, per APWG tracking. The padlock stopped being a trust signal years ago.
  6. Akamai measured 193 billion credential-stuffing attempts across its network in a single year (2020).
  7. Industry estimates from F5 and others put credential-stuffing success rates between 0.1% and about 2%. At billions of attempts, that still means millions of account takeovers.
  8. Microsoft's threat reports document rapid growth in adversary-in-the-middle phishing kits that relay one-time 2FA codes in real time.

How the replay economy behind stats 39 and 40 works - And why one reused password sinks every account - Is laid out in our credential stuffing explainer. The tricks behind stat 36 are dissected in our phishing protection guide.

The fixes: 2FA, managers and passkeys

  1. Microsoft's long-standing finding: multi-factor authentication blocks over 99.9% of automated account-compromise attacks.
  2. Google's 2019 research with NYU and UCSD found on-device prompts blocked 100% of automated bots and 99% of bulk phishing attacks in its study.
  3. Duo Labs surveys tracked 2FA usage climbing from 28% of respondents in 2017 to 79% having used it by 2021. It's one of security's genuine good-news curves.
  4. NIST's SP 800-63B guidance now says it plainly: favor length over composition rules, stop forcing scheduled password changes, and screen new passwords against breached lists.
  5. Surveys consistently show password-manager users reuse credentials far less - Unsurprising, since unique random passwords become free once software remembers them. You can gauge any password's quality in seconds with our password strength checker, which estimates entropy offline in your browser.
  6. Google announced in 2024 that passkeys had been used for over a billion sign-ins across hundreds of millions of Google accounts.
  7. FIDO Alliance surveys show consumer awareness of passkeys has climbed to over half of respondents.
  8. Apple, Google, Microsoft, Amazon and PayPal all ship passkey support, along with hundreds of other services. The post-password era covered in passkeys explained is arriving account by account.
  9. The performance gap that makes cracking possible is enormous. A GPU that tests billions of MD5 guesses per second manages only thousands against bcrypt - A millions-fold slowdown from one engineering choice.
  10. Researchers have repeatedly shown that many router vendors' factory Wi-Fi keys can be derived from the network name itself. That's one reason to replace defaults with a long random key from a WiFi password generator.
  11. One last stat, from Hive Systems' tables, sums up all the others. Going from 8 random characters to 16 moves the crack time from "before your coffee cools" to longer than the age of the universe. Length is the cheapest security upgrade in existence. The mechanics behind that math live in how hackers crack passwords.
Sources for this roundup: Verizon DBIR (2017–2024 editions), IBM Cost of a Data Breach (2024), Have I Been Pwned, NordPass Top 200 Most Common Passwords, LastPass Psychology of Passwords, Google/Harris Poll, Security.org, Bitwarden World Password Day surveys, Hive Systems Password Table, FBI IC3 annual reports, APWG Phishing Activity Trends, Akamai State of the Internet, Microsoft Digital Defense Report, Duo Labs, FIDO Alliance, and NIST SP 800-63B. Figures are quoted from each study's reporting period; year-to-year numbers shift, the patterns don't.

FAQ

What is the most common password in 2026?

Simple number strings still rule. "123456" has finished first in most years of NordPass's annual ranking, trailed by "123456789", "12345678", "password" and "qwerty" variants. All of them fall to cracking tools in under a second, and all of them sit at the very top of the wordlists attackers try first.

How many passwords does the average person have?

NordPass's research puts it around 168 personal passwords per person, and past 250 once work accounts are included. That's far beyond what anyone can memorize as unique strong strings. It's why memory-based password habits collapse into reuse - And why password managers exist.

What percentage of people reuse passwords?

Surveys converge on a majority. Google/Harris found 52% reuse a password across multiple accounts (13% use one everywhere). LastPass found roughly six in ten reuse despite 91% knowing it's risky. Reuse is the single habit that turns one site's breach into a compromise of many accounts.

How fast can a password be cracked?

It depends almost entirely on length, randomness and the site's hashing. Hive Systems' tables show short or common passwords falling instantly on GPU hardware, while a random 16-character password endures for billions of years. Human-chosen passwords underperform their length because dictionary and rule attacks exploit predictable patterns.

Are passkeys really replacing passwords?

Adoption is real but gradual. Google alone has counted over a billion passkey sign-ins, FIDO Alliance surveys show awareness above 50%, and every major platform now supports them. Passwords will linger for years on long-tail sites. So the practical 2026 strategy: passkeys where offered, unique generated passwords plus 2FA everywhere else.