📊 55 Password Security Statistics for 2026: A Primary-Source Reference
On this page
- 1. Attack Scale: What Microsoft Sees in Real Time
- 2. How Breaches Really Start: Verizon DBIR 2025
- 3. The $16.6 Billion Toll: FBI IC3 2024 and IBM 2024
- 4. The Human Behavior Gap: LastPass and SpyCloud
- 5. The Weakest Passwords: What Attackers Already Have
- 6. NIST SP 800-63B: The Policy Baseline (2024 Revision)
- 7. The Passkey Transition: FIDO Alliance 2026
- What These 55 Statistics Mean for Your Password Hygiene Today
- Frequently Asked Questions
📊 55 Password Security Statistics for 2026: A Primary-Source Reference
The statistics in this reference are drawn from primary sources published in 2024, 2025, and 2026: the Verizon Data Breach Investigations Report (DBIR) 2025, the Microsoft Digital Defense Report (MDDR) 2025, the FBI Internet Crime Complaint Center (IC3) 2024 Annual Report, the IBM Cost of a Data Breach Report 2024, the LastPass Psychology of Passwords series, the SpyCloud 2025 Annual Identity Exposure Report, the NordPass Top Passwords 2025 study, the Specops Breached Password Report 2026, and the FIDO Alliance State of Passkeys 2026. Where older studies are cited the year is stated inline. All figures are sourced from the original publication; secondary sources link back to the primary report.
1. Attack Scale: What Microsoft Sees in Real Time
The scale of automated password attacks is difficult to appreciate without raw numbers from providers operating at global infrastructure scale. The Microsoft Digital Defense Report draws on signals across Microsoft Entra ID, Azure, Microsoft 365, and consumer identity services, covering hundreds of millions of accounts.
- Microsoft blocks more than 7,000 password attacks per second across its global infrastructure. (Microsoft Digital Defense Report 2025)
- 97% of all identity attacks are password attacks — spray, stuffing, or brute-force — making the password itself the primary attack surface for any account. (MDDR 2025)
- Identity-based attacks surged 32% in the first half of 2025, driven primarily by large-scale password spraying campaigns targeting accounts with no second factor. (MDDR 2025)
- 85% of usernames targeted in password spray attacks were already present in breach databases — the attackers started with known-exposed email addresses, sourced from credential leaks and underground stealer logs. (MDDR 2025 / Have I Been Pwned cross-reference, May 2025)
2. How Breaches Really Start: Verizon DBIR 2025
The Verizon 2025 Data Breach Investigations Report analysed thousands of confirmed breaches and tens of thousands of incidents worldwide. Credentials remained the single most exploited attack surface for the second consecutive year, even as vulnerability exploitation grew.
- Stolen credentials were the number-one initial access vector for the second consecutive year, appearing across more breach action varieties than any other tactic. (Verizon DBIR 2025)
- Credentials appeared in 22% of all confirmed data breaches in 2025 — down from 31% in the prior report as vulnerability exploitation increased by 34%, but still the leading single cause. (Verizon DBIR 2025)
- In basic web application attacks specifically, stolen credentials rose to 88% of the initial access vector — virtually every web-app breach begins with a compromised username and password. (Verizon DBIR 2025)
- Credential stuffing accounts for 19% of all authentication attempts on a median daily basis — meaning roughly one in five login attempts a typical organisation sees is an automated attack replaying stolen credentials. (Verizon DBIR 2025)
- Only 49% of a user’s passwords across different services are unique; the remaining 51% are reused or trivially varied, giving attackers a large pool of exploitable credentials from any single breach. (Verizon DBIR 2025, infostealer infection data)
- Credential-related breaches cost an average of $4.81 million per incident once direct, indirect, and regulatory costs are counted. (Verizon DBIR 2025)
- The average time to detect and contain a credential breach is 292 days — nearly ten months of undetected attacker access during which data can be exfiltrated at will. (Verizon DBIR 2025)
3. The $16.6 Billion Toll: FBI IC3 2024 and IBM 2024
Credential theft translates directly into financial loss. The FBI Internet Crime Complaint Center’s 2024 Annual Report and the IBM Cost of a Data Breach Report 2024 quantify that damage in concrete dollar terms.
- Internet crime cost victims $16.6 billion in 2024 — a 33% increase from 2023 and the largest single-year loss total the FBI IC3 has recorded since its founding. (FBI IC3 Annual Report 2024)
- The average loss per cybercrime complaint rose to $19,372 in 2024, up from $14,197 in 2023 — a 37% increase in average victim impact. (FBI IC3 2024)
- Phishing and spoofing was the most commonly reported cybercrime in 2024, with more than 193,000 complaints and $70 million in reported losses. (FBI IC3 2024)
- Business email compromise caused $2.77 billion in losses in 2024 — virtually all BEC attacks begin with a compromised, guessed, or spoofed email credential. (FBI IC3 2024)
- Cyber fraud represented 83% of all losses reported to IC3, accounting for 333,981 complaints and $13.7 billion in total damages. (FBI IC3 2024)
- The average global data breach cost reached $4.88 million in 2024 — the largest single-year jump since the pandemic era, according to a study of 604 organisations across 17 industries and 16 countries. (IBM Cost of a Data Breach Report 2024)
- Healthcare breaches averaged $9.77 million per incident — the highest cost of any industry sector studied — for the fourteenth consecutive year. (IBM 2024)
- Financial sector breaches averaged $6.08 million, 22% above the global mean, reflecting high regulatory, notification, and reputational costs. (IBM 2024)
- Organisations that extensively used AI and automation in prevention workflows spent $2.2 million less per breach on average than those with no such tools. (IBM 2024)
4. The Human Behavior Gap: LastPass and SpyCloud
The statistics above describe attacker capabilities. Those below reveal why attacks succeed: a persistent, well-documented gap between what people know about password security and what they actually practise. This gap persists even after security training.
- 91% of people know that reusing passwords across accounts is a security risk — yet 66% do it anyway. (LastPass Psychology of Passwords, 2020)
- 92% acknowledge the risk of password reuse; 65% continue to reuse passwords across multiple accounts. (LastPass Psychology of Passwords, 2021)
- 75% of respondents report high confidence in managing their passwords — while two-thirds simultaneously reuse the same password or a minor variation. (LastPass Psychology of Passwords)
- After receiving cybersecurity training, only 31% of users stopped reusing passwords — illustrating the fundamental limits of awareness campaigns without tooling. (LastPass)
- 68% of respondents would create a strong password for a financial account; only 32% would apply the same standard to their work accounts. (LastPass Psychology of Passwords)
- SpyCloud recaptured 53.3 billion distinct identity records in 2024, a 22% increase from 2023, reflecting the scale and growth of dark-web credential markets. (SpyCloud Annual Identity Exposure Report 2025)
- 3.1 billion exposed passwords were recaptured in 2024 — a 125% year-over-year increase driven by a surge in infostealer malware deployments. (SpyCloud 2025)
- 70% of users exposed in a breach later reused their compromised password on at least one other site, extending their own exposure window indefinitely. (SpyCloud 2025)
- 91% of organisations suffered an identity-related security incident in the past year — nearly double the proportion reported in the prior-year survey. (SpyCloud 2025)
- 17.3 billion session cookies were recaptured from malware-infected devices in 2024, enabling attackers to bypass MFA entirely by hijacking active browser sessions rather than cracking passwords. (SpyCloud 2025)
- 548 million credentials were stolen by infostealer malware in 2024. (SpyCloud 2025)
- Public-sector organisations had a 67% all-time password reuse rate among employees — a 13-percentage-point increase over the prior year — based on SpyCloud’s analysis of 127,000 recaptured .gov credentials. (SpyCloud 2025)
- Nearly 80% of breaches involve stolen or compromised credentials at some point in the attack chain — either as the initial vector or for lateral movement inside the network. (SpyCloud 2025)
5. The Weakest Passwords: What Attackers Already Have
Weak passwords are not hypothetically exploitable — they are actively exploited, at scale, right now. The NordPass Top Passwords 2025 study analysed leaked data from 44 countries. The Specops Breached Password Report 2026 examined over 6 billion infostealer-stolen credentials collected during 2025.
- “123456” has held the top spot as the most common global password for six out of the seven years NordPass has published this data — and it can be cracked in under one second. (NordPass Top Passwords 2025)
- “admin” is the most common password in the United States in 2025, primarily because router, switch, and IoT device default credentials are routinely left unchanged. (NordPass 2025)
- The word “password” appears in every annual NordPass top-20 list since the study began — despite more than a decade of public awareness campaigns. (NordPass 2025)
- 6 billion passwords were stolen by malware in 2025, analysed and published in the Specops 2026 Breached Password Report. (Specops Software 2026)
- 230 million of those stolen passwords met traditional complexity requirements — at least 8 characters, one uppercase letter, one number, and one symbol — proving complexity rules alone do not prevent compromise. (Specops 2025)
- 98.5% of breached passwords are under 15 characters, supporting NIST’s position that length is the single most important factor in password resilience. (Specops 2025/2026)
- LummaC2 was responsible for nearly 60% of all infostealer-attributed credentials stolen in 2025, followed by RedLine, Vidar, Stealc, Rhadamanthys, and RisePro. (Specops Breached Password Report 2026)
6. NIST SP 800-63B: The Policy Baseline (2024 Revision)
NIST’s password guidelines shape policy for US federal agencies and are widely adopted by enterprise security teams globally. The 2024 revision made two headline changes that affect anyone setting password policies.
- NIST SP 800-63B (2024 revision) removed mandatory complexity requirements — rules mandating uppercase letters, numbers, and symbols — in favour of length, setting a minimum of 8 characters with 15 or more strongly recommended. Complexity rules were found to produce predictable substitutions (“P@ssw0rd”) without improving entropy. (NIST SP 800-63B, 2nd Public Draft, 2024)
- NIST SP 800-63B now requires that new passwords be checked against a list of known compromised passwords at the point of account creation or password change — a control that remains absent from most consumer websites and many enterprise platforms. (NIST SP 800-63B, 2024)
7. The Passkey Transition: FIDO Alliance 2026
Passkeys — FIDO2-based credentials that use device-bound cryptographic keys instead of a shareable secret — are the primary industry replacement for passwords. The FIDO Alliance State of Passkeys 2026 report draws on two parallel Sapio Research studies conducted in April 2026, surveying 11,000 consumers across ten countries and 1,400 decision-makers at organisations with 500 or more employees.
- 5 billion passkeys are now in active use worldwide. (FIDO Alliance State of Passkeys 2026)
- 90% of consumers are now aware of passkeys in 2026, up significantly from 75% in the 2025 World Passkey Day report. (FIDO Alliance 2026)
- 75% of consumers have enabled a passkey on at least one account. (FIDO Alliance 2026)
- 49% of consumers use passkeys regularly when the option is available. (FIDO Alliance 2026)
- Passkeys achieve a 93% login success rate, versus 63% for traditional password-based login flows. The gap reflects fewer forgotten credentials and no susceptibility to phishing. (FIDO Alliance 2026)
- 68% of organisations have deployed or are actively deploying passkeys for employee sign-ins. (FIDO Alliance 2026)
- 82% of enterprises aim to reach a fully passwordless environment. (FIDO Alliance 2026)
- 28% of organisations have already completely eliminated legacy password credentials from their internal systems. (FIDO Alliance 2026)
- Google accounts for roughly half of all measured passkey activity; 800 million Google accounts now use passkeys following the platform’s late-2023 default-on rollout. (Google / FIDO Alliance 2025)
- Google’s passkey authentications grew 352% after passkeys became the default sign-in option in late 2023. (FIDO Alliance 2025)
- 1.3 billion passkey authentications now occur every month — double the figure from one year earlier. (FIDO Alliance Passkey Index, 2025)
- Microsoft made passkeys the default sign-in for all new accounts in May 2025, driving a 120% increase in passkey authentications across its ecosystem within weeks of the rollout. (Microsoft 2025)
- Despite rapid consumer deployment, 57% of organisations with passkeys still rely on phishable authentication methods for primary daily sign-in — meaning the full transition from passwords remains incomplete for the majority. (FIDO Alliance 2026)
For a deeper look at the credential stuffing patterns behind statistics 7 and 8, see our guide on credential stuffing statistics. For the human behaviour patterns in section 4, see our password habits statistics. For passkey details, our passkey statistics post provides expanded coverage.
What These 55 Statistics Mean for Your Password Hygiene Today
Three evidence-based actions follow directly from the data above.
- Use a password manager. It eliminates reuse (statistics 9, 21–24, 28), generates passwords longer than 15 characters (stat 40), and ensures every account has a unique credential that an attacker cannot exploit across services.
- Enable a phishing-resistant second factor everywhere. Session-cookie hijacking (stat 30) defeats SMS OTP because it bypasses the authentication step entirely. A FIDO2 security key or a passkey is bound to the legitimate domain and cannot be replayed on a fake site.
- Adopt passkeys where available. With a 93% success rate (stat 47) and zero susceptibility to phishing, credential stuffing, or spray attacks, passkeys directly address the root cause behind statistics 5–9 and 34–40.
Protect every account with a dedicated password manager
NordPass generates long, random, unique passwords for every site, stores them with XChaCha20 encryption, and automatically flags credentials that appear in breach databases.
Get NordPass — up to 60% off →Affiliate link — see our disclosure.
Frequently Asked Questions
How many password attacks happen every second in 2026?
According to Microsoft’s Digital Defense Report 2025, Microsoft alone blocks more than 7,000 password attacks every second across its global identity infrastructure. The true global figure, across all platforms and services, is considerably higher. These attacks are primarily automated spray and stuffing campaigns replaying credentials from breach dumps.
What percentage of data breaches involve stolen passwords?
The Verizon DBIR 2025 found stolen credentials in 22% of all confirmed data breaches, making them the leading initial access vector for the second consecutive year. In basic web application attacks specifically the figure rises to 88%. SpyCloud’s 2025 report found that nearly 80% of breaches involve stolen or compromised credentials at some point in the attack chain.
What was the total cost of cybercrime in 2024?
The FBI Internet Crime Complaint Center 2024 Annual Report recorded losses exceeding $16.6 billion — a 33% increase from 2023 and the highest total since IC3 began publishing annual reports. Business email compromise alone accounted for $2.77 billion of that figure, while phishing and spoofing was the most frequently reported crime type.
What is the most common password in 2025?
According to the NordPass Top Passwords 2025 study, “123456” held the global top spot for the sixth time in seven years. In the United States, “admin” was the most commonly used password, primarily because it is the default credential on routers, switches, and IoT devices that users never change.
How many passkeys are in use in 2026?
The FIDO Alliance State of Passkeys 2026 report estimates that 5 billion passkeys are now in active use worldwide. Google alone has 800 million accounts using passkeys, with authentications growing 352% since it made passkeys the default sign-in option in late 2023. The global monthly total reached 1.3 billion authentications in 2025 — double the prior year’s figure.
Are complex passwords with symbols still required by NIST?
No. NIST SP 800-63B’s 2024 revision removed mandatory complexity requirements. NIST now emphasises length (minimum 8 characters, 15 or more strongly recommended) and checking new passwords against known compromised credential lists at the point of creation. Mandatory uppercase, number, and symbol requirements were removed because they led to predictable substitutions without meaningfully increasing entropy.
What percentage of users reuse passwords after a breach?
SpyCloud’s 2025 Annual Identity Exposure Report found that 70% of users exposed in a breach later reused their compromised password on at least one other site. Separately, the Verizon DBIR 2025 found that only 49% of a user’s passwords across services are unique. LastPass’s Psychology of Passwords research found that 91% of people know reuse is risky, yet 66% do it anyway.
What is the average cost of a data breach in 2024?
The IBM Cost of a Data Breach Report 2024 put the global average at $4.88 million per incident across 604 organisations in 17 industries and 16 countries — the largest single-year increase since the pandemic era. Healthcare remained the most expensive sector at $9.77 million per breach for the fourteenth consecutive year. Organisations using AI extensively in breach prevention saved an average of $2.2 million per incident.