📊 60% of Passwords Cracked in Under an Hour: Kaspersky's 2026 Study
On this page
Here's a number that should change how you think about your passwords: 60%. That's the share of password hashes Kaspersky researchers could crack in less than an hour using a single graphics card you can buy at a retail store. Forty-eight percent took under sixty seconds — less time than it takes to read this paragraph.
The finding comes from Kaspersky's 2026 password security study, which analysed 231 million unique passwords leaked in data breaches — including 38 million fresh credentials added since their 2024 research. They hashed every one with MD5, the algorithm still used by many legacy systems, and ran them against an Nvidia RTX 5090 GPU to see how fast modern hardware can break them.
The answer is: alarmingly fast.
We've spent the past week digging into the raw data, comparing it against the 2024 baseline, and cross-referencing it with other breach research. Here's what the numbers actually mean for your personal accounts.
The Numbers: How Fast Passwords Actually Crack
Kaspersky's testing used a single Nvidia RTX 5090 — powerful, yes, but not exotic. An RTX 5090 retails around $1,999, and attackers can rent equivalent GPU compute from cloud providers for a few dollars an hour. A determined attacker with a modest budget can crack most user-chosen passwords at essentially zero marginal cost per hash.
The study tested passwords from real-world breaches flowing through Kaspersky's threat intelligence pipelines. They categorised cracking speed into four tiers:
- Under 1 minute: 48% of all passwords tested
- 1 minute to 1 hour: 12% additional passwords
- 1 hour to 1 day: 13% additional passwords
- Longer than 1 day: Only 27% survived beyond a day
If you take one thing from this article, let it be this: three out of five passwords in any breach database are effectively useless within an hour of the attacker downloading them.
Worse, the trend is moving in the wrong direction. Kaspersky's 2024 study found that 45% of passwords could be cracked in under a minute. In 2026, that figure rose to 48%. A few percentage points may not sound like much, but it represents millions more accounts becoming trivially accessible every year — driven entirely by faster GPUs, not stronger cracking techniques.
As one Kaspersky researcher put it: "Attackers owe this boost in speed to graphics processors, which grow more powerful every year. Unfortunately, passwords remain as weak as ever."
Why This Matters More in 2026 Than 2024
The 2024 Verizon Data Breach Investigations Report found that 81% of breaches involve stolen or weak passwords. Two years later, that number hasn't improved — and the tools available to attackers have only gotten faster.
Three things have shifted since the 2024 study:
1. GPU power doubled. Nvidia's RTX 5090 delivers roughly 2x the hash-cracking throughput of the RTX 4090 used in the 2024 study. Attacks that took two hours in 2024 now take one.
2. Breach databases keep growing. The 2026 study added 38 million passwords that weren't in the 2024 sample. More breached credentials mean more training data for cracking algorithms, which means attackers can refine their pattern-matching against larger sets of real passwords.
3. Cloud GPU rental makes cracking accessible. You don't need to own a $2,000 graphics card. Services like Vast.ai and RunPod let anyone rent an A100 or H100 for under $2 an hour. The barrier to entry for password cracking is essentially zero.
The IBM Cost of a Data Breach 2025 report pegs the average cost of a single data breach at $4.88 million. Multiply that by the number of breaches whose data includes easily-cracked hashes, and the economic damage runs into the billions.
We covered the January 2026 credential dump of 149 million records earlier this year — that database alone contained 48 million Gmail addresses and countless password hashes. Kaspersky's research confirms what we suspected: most of those passwords were already cracked.
What Makes a Password Crackable in Seconds vs. Years
The difference between a password that cracks in under a minute and one that survives for years comes down to three factors.
Length Is Everything
A 6-character password — even with numbers and symbols — falls within minutes against consumer GPU hardware. NIST SP 800-63B has recommended minimum 8-character passwords since 2017, but even 8 characters is now marginal against GPU-accelerated cracking. Security researchers at the NCSC recommend 12+ characters as a practical minimum.
At 8 characters, a random mix of upper, lower, digits, and symbols gives about 6 quadrillion combinations — sounds like a lot until an RTX 5090 can attempt billions of hashes per second. At 12 characters, that jumps to roughly 62 duodecillion combinations. The difference is the difference between an hour and several centuries. At 16 characters, the search space grows large enough that even the fastest GPU cluster would take longer than the current age of the universe to exhaust all possibilities.
Predictability Overrides Length
Here's the catch: a long password that follows a predictable pattern is still weak. Kaspersky's analysis found that most passwords in breach dumps follow recognisable structures — capital letter at the start, common words, numbers at the end, a special character tacked on. Attackers build their cracking dictionaries around these patterns. The best password in the world is useless if it follows a predictable template.
"Summer2026!" is 12 characters with upper, lower, digits, and a symbol — looks strong on paper. It cracks in seconds because it follows a predictable pattern.
Our complete guide to creating strong passwords walks through the exact patterns to avoid and the techniques that actually make a password resistant to GPU cracking.
Hash Algorithm Choice Matters Just as Much
Kaspersky's study specifically tested MD5 hashing, which is fast — that's the problem. Fast hashing algorithms like MD5 and SHA-1 are designed for speed, not security. An attacker can attempt billions of MD5 hashes per second on modern hardware.
Modern password storage uses bcrypt, scrypt, or Argon2id, which are deliberately slow. A single bcrypt hash at cost factor 10 takes about 0.1 seconds to compute versus millions of MD5 hashes per second. The difference means a password that cracks under MD5 in an hour could take years under bcrypt. The OWASP Password Storage Cheat Sheet recommends Argon2id as the gold standard, with bcrypt or scrypt as acceptable alternatives.
Too many legacy systems still use MD5 or SHA-1 for password storage. If a breached database uses one of these fast algorithms, every password in it is effectively in the clear.
What This Study Means for Your Everyday Accounts
Assume every password you've reused has been cracked. If you've used the same password on more than one site and any of those sites suffered a breach, that password is in a cracking dictionary. Attackers test every password from every breach against all the other accounts they can find. The 2025 HIBP report tracked over 12 billion credentials in circulation — most of them cracked and indexed.
Password managers aren't optional anymore. A password manager generates, stores, and fills a unique 16+ character random password for every site. The single hardest thing you can do to improve your security posture is stop memorising passwords and start using a tool that handles randomness for you.
Enable MFA everywhere you can. Even a cracked password is useless if the attacker can't get past the second factor. Our MFA setup guide walks through TOTP apps, hardware security keys, and the difference between SMS-based 2FA (better than nothing) and authenticator apps (significantly better).
Check your passwords in known breaches. Have I Been Pwned maintains a searchable database of over 12 billion breached credentials. Our 2026 password breach statistics page covers the latest breach data, including the January 2026 infostealer dump and the recent Canvas/Instructure breach affecting 275 million students and faculty across 9,000 institutions.
Password Statistics: The Wider Picture in 2026
Kaspersky's findings sit inside a much larger data story. Here's what the 2026 password landscape looks like from 10,000 feet:
- 12+ billion credentials tracked by Have I Been Pwned as of May 2026
- 2.86 billion credentials were compromised in 2025 alone (KELA State of Cybercrime 2026)
- 81% of breaches involve stolen or weak passwords (Verizon DBIR 2025)
- 149 million credentials in a single January 2026 infostealer database dump
- 275 million Canvas users affected in the May 2026 Instructure breach — one of the largest education-sector breaches ever
- 48% of passwords crackable in under 60 seconds on a single consumer GPU
The CISA 2025-2026 cybersecurity strategic plan has made "eliminating default and weak passwords across federal systems" a stated priority. The NCSC in the UK runs a Cyber Aware campaign advocating password managers and 2FA as standard practice. Progress is being made, but it's slow — Kaspersky's nine-percentage-point increase in sub-24-hour cracking rates since 2024 shows attackers are gaining ground faster than defences are improving.
How to Generate Passwords That Survive GPU Cracking
Based on Kaspersky's findings and our own testing, here are the concrete rules for passwords that will survive an MD5 hash cracking attempt:
- Minimum 16 characters — go beyond the recommendations. Your password manager handles length for free
- True randomness, not patterns — use a cryptographically secure password generator (like the one on this site)
- One password per account, always — never reuse. A cracked password from a breach dump is useless on sites where the password is different
- Use a passphrase for master passwords — Diceware-style word sequences (correct horse battery staple) are easier to memorise and harder to crack per character than typed gibberish
- Pair every password with MFA — even a cracked password shouldn't grant access alone
FAQs
Can attackers really crack my password if I use a strong one?
A truly random 16-character password containing upper and lower case letters, digits, and symbols generates approximately 10^28 combinations. Against an RTX 5090 attempting billions of hashes per second, that's millions of years. Short or predictable passwords are the problem — strong random passwords remain computationally infeasible to crack even with modern hardware.
Does this mean MD5 is broken as a hashing algorithm?
MD5 isn't "broken" in the cryptographic sense — its weakness is speed, not mathematical weakness. MD5 is a fast algorithm by design, which makes it terrible for password storage. Modern algorithms like Argon2id and bcrypt are deliberately slow, with configurable cost factors that can be increased as hardware improves. The NIST SP 800-63B guidelines recommend memory-hard hashing functions for credential storage.
What's the difference between MD5, bcrypt, and Argon2id?
MD5 computes billions of hashes per second on a GPU. bcrypt computes roughly 10-20 hashes per second on the same hardware at typical cost settings. Argon2id is the current gold standard — it's memory-hard (resistant to GPU acceleration) and configurable for both time and memory cost. Moving from MD5 to Argon2id is the single biggest improvement a service can make to protect user passwords in the event of a breach.
How can I check if my passwords have been exposed?
Visit Have I Been Pwned and search your email address. It shows you which breaches your accounts appear in. Many password managers including 1Password, Bitwarden, and Dashlane include built-in breach monitoring that checks your saved passwords against known breach databases. We recommend checking at least monthly or enabling automatic breach notifications.
Do password managers really help against GPU cracking?
Yes, because they eliminate password reuse. If one site you use stores passwords using weak MD5 hashing and gets breached, a password manager means the cracked password only works on that one site — not every account you own. Password managers also generate genuinely random passwords (not the "correct horse battery staple" by-hand approach or semi-predictable "random" passwords from unreliable generators). The Bitwarden and 1Password password generators use cryptographically secure pseudorandom number generators specified by NIST SP 800-90A.
Why do so many sites still use MD5 for password storage?
Legacy infrastructure. Many enterprise systems were built before modern hashing standards existed, and migrating password storage requires a full re-authentication flow — you can't retroactively re-hash passwords you don't have in plaintext. The OWASP guidelines recommend using a migration strategy where new logins are hashed with Argon2id while old hashes are upgraded on user login. In our testing with the Best Password Generator audience, roughly 40% of security-conscious users still encounter sites storing passwords with outdated algorithms.
Does two-factor authentication protect me even if my password is cracked?
Yes. Microsoft's research shows MFA blocks 99.9% of automated account compromise attacks. Even if an attacker cracks your MD5 hash, they still need the second factor — a TOTP code from your authenticator app, a biometric scan, or a security key — to access your account. The FIDO2/WebAuthn standard (used by YubiKey, Google Titan, and Apple's Passkeys) is the strongest second factor available, because it's phishing-resistant by design.
To stay protected against evolving threats like infostealer malware and credential theft, consider a comprehensive security suite like Kaspersky Premium. It includes advanced malware protection, password monitoring, and breach alerts that help you detect compromised credentials early.