📊 50 Password Statistics 2026 — Updated Primary-Source Facts
These password statistics for 2026 are compiled from primary-source reports: the Verizon Data Breach Investigations Reports (DBIR 2025 and 2026), the Microsoft Digital Defense Report 2025, the FBI Internet Crime Complaint Center Annual Report 2025, the IBM Cost of a Data Breach Report 2025, the LastPass Psychology of Passwords study, NordPass Most Common Passwords 2025, the Specops Breached Password Reports (2025 and 2026), Have I Been Pwned, and NIST Special Publication 800-63B Revision 4 (finalized July 2025). Each statistic is attributed inline. Where a number depends on methodology, the source and year are stated so you can verify it independently.
They answer four questions that shape real security decisions: how password attacks happen at scale, how much they cost when they succeed, why human habits keep the door open, and what the guidance and technology landscape looks like heading into 2027.
Key Statistics at a Glance
1. The Scale of Password Attacks
These figures come from the Microsoft Digital Defense Report 2025 (MDDR), which aggregates signals from Microsoft’s global cloud and identity infrastructure across hundreds of millions of accounts. They show the relentless, automated nature of modern credential attacks.
- Microsoft observed an average of more than 7,000 password attacks per second in 2024, equivalent to roughly 600 million attacks every day. (Microsoft Digital Defense Report, 2025)
- 97% of all identity-based attacks are password-spray or brute-force attacks — automated tools test one common password against thousands of accounts simultaneously. (Microsoft MDDR, 2025)
- Identity-based attacks surged 32% in the first half of 2025 compared with the same period a year earlier — the steepest half-year rise on record. (Microsoft MDDR, 2025)
- 85% of usernames targeted in password-spray attacks already appeared in at least one prior data-breach log, each associated on average with three separate breach datasets. (Microsoft MDDR, 2025)
- Of all observed login attempts during credential attacks, 45% used a valid username with the wrong password and only 1.5% used correct credentials — which were then blocked by multi-factor authentication. (Microsoft MDDR, 2025)
2. Breaches & Credential Theft
The Verizon Data Breach Investigations Report (DBIR) is the security industry’s most-cited breach dataset. The 2025 edition analysed more than 12,000 confirmed breaches; the 2026 edition extended the dataset and documented a historic shift in initial-access tactics.
- Stolen credentials were the single most common initial access vector, appearing in 22% of confirmed breaches in the 2025 DBIR dataset — the highest-ranked initial action for the second consecutive year. (Verizon DBIR, 2025)
- 88% of basic web-application attacks involved stolen or compromised credentials, making login forms the primary attack surface for web-facing systems. (Verizon DBIR, 2025)
- In analysed single-sign-on infrastructure, credential stuffing accounted for a median 19% of all daily authentication attempts — nearly 1 in 5 login requests is an automated attack probe. (Verizon DBIR, 2025)
- In the median case, only 49% of a user’s passwords were distinct from each other, meaning more than half were duplicates reused across different services. (Verizon DBIR, 2025)
- For the first time in the DBIR’s 19-year history, software vulnerability exploitation overtook stolen credentials as the top initial access vector, reaching 31% of breaches in the 2026 edition. (Verizon DBIR, 2026)
- Despite no longer being the top initial vector, credentials still appear somewhere in 39% of all breach chains when counted at any stage of an attack. (Verizon DBIR, 2026)
- Ransomware appeared in 48% of all breaches in the 2026 DBIR — the highest figure in the report’s history, up from 44% the previous year. (Verizon DBIR, 2026)
3. The Financial Impact
Credential theft is expensive in both direct remediation costs and the extended dwell time that typically precedes discovery. The IBM and FBI IC3 figures below capture this from two angles: average per-breach cost and aggregate national cybercrime losses.
- Breaches initiated by compromised credentials cost an average of $4.67 million per incident — one of the most expensive breach categories in the 2025 study. (IBM Cost of a Data Breach, 2025)
- Credentials were the data type compromised in 53% of all data breaches studied, making them the single most targeted class of information. (IBM, 2025)
- Credential-based breaches have an average detection-and-containment lifecycle of 246 days — more than eight months of silent, unauthorized access before the breach is identified and closed. (IBM, 2025)
- Breaches lasting more than 200 days cost approximately $5.01 million on average, versus $3.87 million for those contained more quickly — a $1.14 million premium for slow detection. (IBM, 2025)
- US cybercrime losses reached $20.877 billion in 2025 — a 26% increase in a single year and the largest annual jump on record. (FBI IC3 Annual Report, 2025)
- The FBI IC3 received 1,008,597 complaints in 2025, the first time annual complaint volume has exceeded one million in the centre’s 25-year history. (FBI IC3, 2025)
- Account takeover (ATO) fraud generated 5,100+ IC3 complaints with $262 million in direct losses in 2025 — formally acknowledged as a distinct growing threat category for the first time in the annual report. (FBI IC3, 2025)
- The IC3 received over 22,000 AI-related cybercrime complaints in 2025, with adjusted losses exceeding $893 million, establishing AI as a primary amplification tool for credential-based fraud campaigns. (FBI IC3, 2025)
4. Human Password Habits
Despite widespread public awareness campaigns, research consistently shows that most people continue to use weak, reused passwords. The statistics below are drawn from the LastPass Psychology of Passwords global study and multiple 2024–2025 consumer surveys.
- 92% of people know that reusing the same password is a security risk, yet 65% still do it across multiple services anyway. (LastPass Psychology of Passwords)
- Only 12% of individuals always create a unique password for each account — the remaining 88% reuse passwords in some form across at least some accounts. (LastPass)
- Gen Z reuses a single password or a close variation 69% of the time, despite being the most digitally native generation. (LastPass)
- 57% of users update passwords by modifying an existing one — appending a digit, capitalising a letter, or adding a symbol to the end — a substitution pattern that attackers specifically predict and exploit with rule-based cracking. (GoDaddy Consumer Pulse, 2025)
- Among users who rarely or never use unique passwords, 62% cite “difficulty remembering different passwords” as their primary reason for not changing their habits. (consumer survey, 2025)
- 61% of consumers admit to reusing passwords across their online accounts as of 2025, despite widespread awareness of the risk. (GoDaddy Consumer Pulse, 2025)
- 68.89% of all breached credentials found in 2025 were stored in plaintext by the services that held them — a 261% increase year-over-year, indicating that server-side security failures compound end-user password risk. (Constella Intelligence, 2025)
- Infostealer malware yielded 51.7 million credential packages in 2025, driving a 661% surge in breaches containing personally identifiable information. (Constella Intelligence / FBI IC3, 2025)
5. The Password Landscape
Annual analyses by NordPass, Specops Software and the Have I Been Pwned project document both the composition of weak passwords actively in use and the scale of the credential economy that feeds attack toolkits. The numbers below reflect data collected and published through 2025 and 2026.
- “123456” has topped the global most-common-password list for 6 of the 7 years NordPass has published the research — consistent across all age groups surveyed. (NordPass, 2025)
- In the United States specifically, “admin” surpassed “123456” to become the #1 most common password in 2025. (NordPass, 2025)
- 78% of the 200 most common passwords can be cracked in under one second using freely available brute-force tools. (NordPass, 2025)
- NordPass found that password quality is equally poor across all generational groups — “12345” and “123456” consistently emerge as top choices for every age bracket studied. (NordPass, 2025)
- Compared with 2024, the 2025 NordPass list shows 32 passwords in the top 200 now include special characters, up from just 6 the previous year — the first meaningful shift in seven years of tracking. (NordPass, 2025)
- The five most-stolen passwords in 2025 were: “123456”, “123456789”, “12345678”, “admin”, and “password” — all crackable in milliseconds. (Specops Breached Password Report, 2025)
- Specops analysed more than 6 billion passwords stolen by malware in 2025 alone — six times the 1.09 billion analysed in their 2024 edition. (Specops, 2026)
- 98.5% of those 6 billion breached passwords were weak by definition: under 15 characters or using fewer than two character classes. (Specops, 2025)
- Despite their weakness, 230 million stolen passwords still met traditional complexity rules (8+ chars, one capital, one number, one symbol), proving that complexity rules alone do not prevent credential theft. (Specops, 2025)
- In November 2025, Have I Been Pwned absorbed the Synthient corpus: 1.96 billion unique email addresses and 1.3 billion unique passwords, of which 625 million passwords had never previously appeared in the database. (Have I Been Pwned, November 2025)
- As of 2025, Have I Been Pwned indexes over 2 billion email addresses from more than 1,038 separate confirmed data breaches. (HIBP, 2025)
- Cumulative global password exposure grew from approximately 16 billion passwords in 2023 to 19 billion by mid-2025. (Stingrai analysis, 2025)
Source: Verizon DBIR 2026. Percentages reflect the first recorded action in confirmed breaches. All credential-related actions across the full attack chain appear in 39% of breaches.
6. NIST Password Guidelines 2025
NIST Special Publication 800-63B Revision 4, finalized in July 2025, is the most significant update to US federal password guidance in a decade. It shifts focus from complexity rules to length, breach-checking, and phishing-resistant authentication — and its recommendations increasingly influence enterprise password policies worldwide.
- NIST SP 800-63B-4, finalized in July 2025, introduces phishing-resistant authentication, explicit passkey support, and the formal prohibition of knowledge-based authentication (security questions) for identity verification. (NIST, July 2025)
- When a password is the sole authenticator, Revision 4 requires a minimum of 15 characters — a substantial increase from the implied 8-character minimum in the previous version. (NIST SP 800-63B-4, 2025)
- NIST now explicitly prohibits mandatory periodic password expiration: passwords should only be changed when a compromise is detected or the user voluntarily requests it. Forced 90-day rotations are prohibited. (NIST SP 800-63B-4, 2025)
- Complexity composition rules are prohibited as the primary security mechanism — NIST bans “must contain one uppercase, one number, one symbol” policies, which do not prevent credential stuffing. (NIST SP 800-63B-4, 2025)
- NIST requires all newly chosen passwords to be screened against compromised-credential databases at the point of creation, preventing users from selecting any known-breached password. (NIST SP 800-63B-4, 2025)
7. MFA Adoption & the Path Forward
Multi-factor authentication — especially phishing-resistant forms such as FIDO2 and passkeys — is the single most effective technical control against credential attacks. These statistics show both its proven effectiveness and the deployment gap that still persists.
- Phishing-resistant MFA blocks over 99% of identity-based attacks, even when the attacker already has the correct username and password. (Microsoft Digital Defense Report, 2025)
- More than 99.9% of accounts that were compromised had no MFA enabled at the time of the attack — a figure consistent across multiple annual Microsoft security reports. (Microsoft)
- Roughly 70% of enterprise users had adopted some form of MFA by 2025, leaving approximately 30% of enterprise accounts still relying on passwords as the sole authentication factor. (survey aggregate, 2025)
- MFA adoption varies sharply by organisation size: 87% of companies with 10,000+ employees use MFA, while only ~34% of small businesses have deployed any form of second factor. (enterprise security survey, 2025)
- Two-factor authentication (2FA) reached 78% adoption for personal accounts and 73% for work accounts worldwide — growth of roughly 10 percentage points in two years. (Bitwarden State of Password Management, 2024)
🔑 The Practical Step: Use a Password Manager
The statistics above make the root cause clear: password reuse and weak passwords drive the majority of credential breaches. A password manager eliminates both problems — it generates a long, unique password for every account and stores them securely, so you never have to remember (or reuse) any of them.
Try NordPass Free →Sponsored link — we may earn a commission at no extra cost to you. See our affiliate disclosure.
Frequently Asked Questions
What percentage of data breaches involve stolen passwords in 2026?
According to the Verizon DBIR 2026, credentials appear somewhere in 39% of all breach chains when counted at any stage of an attack. As the initial access vector specifically, credential theft dropped from 22% (DBIR 2025) to 13% (DBIR 2026) as software exploits overtook it — but credentials remain a dominant factor throughout the full attack lifecycle.
What are the most common passwords in 2025?
According to NordPass 2025, “123456” remains the most common password globally, topping the list for the sixth time in seven years. In the United States, “admin” is #1. The five most-stolen passwords found in breached datasets (Specops 2025) were: “123456”, “123456789”, “12345678”, “admin”, and “password” — all crackable in milliseconds with standard tools.
How much does a credential-based data breach cost in 2025?
The IBM Cost of a Data Breach Report 2025 puts the average at $4.67 million per credential-based breach. These breaches also take the longest to resolve — an average of 246 days from intrusion to containment. Breaches undetected for more than 200 days cost an average $5.01 million, compared with $3.87 million for faster-detected incidents.
Does multi-factor authentication actually stop password attacks?
Yes — dramatically. Microsoft’s MDDR 2025 states that phishing-resistant MFA (FIDO2/passkeys) blocks over 99% of identity-based attacks, even when attackers have valid credentials. Critically, more than 99.9% of compromised accounts had no MFA enabled. The challenge is deployment: only ~70% of enterprise users have any MFA, and most use less secure SMS or app-based TOTP forms rather than phishing-resistant FIDO2.
What does NIST recommend for passwords in 2025?
NIST SP 800-63B Revision 4, finalized July 2025, makes four key policy changes: (1) minimum 15 characters when password is the sole authenticator; (2) no mandatory expiration — change only when compromised; (3) no composition rules (the “one uppercase, one number” approach is explicitly prohibited); and (4) all new passwords must be screened against known-breached credential lists at the time of creation.