Recent research highlights the persistent risk posed by weak passwords, with modern password cracking tools able to compromise a significant portion of real-world credentials in under an hour. Analysis of over 190 million passwords reveals that nearly 60% can be cracked within sixty minutes, largely due to the power of contemporary GPUs and advanced brute-force and dictionary attack techniques. Security experts emphasize the importance of adopting stronger authentication strategies, such as using passphrases and password managers, to mitigate these risks and prevent unauthorized access to sensitive systems and data.
Longitudinal studies of leaked password datasets from 2007 to 2025 show that user habits and password strength have improved over time, particularly following major breach events and the introduction of stricter password policies. The adoption of machine-generated passwords and built-in password managers in operating systems has contributed to measurable progress, though a minority of users still rely on weak, easily guessed credentials. Security professionals recommend continued education and the implementation of advanced password management tools to address remaining gaps and further strengthen enterprise security posture.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A subsequent report highlighted recent research indicating that almost 60% of real-world passwords can be cracked within an hour using modern password-cracking tools and hardware. The coverage emphasized the continued risks from short, predictable, reused passwords and recommended password managers, passphrases, and MFA.
On publication, Flare-backed research summarized two decades of leaked-password data and concluded that overall password security has improved, though weak-password use persists among some users. The study highlighted the positive impact of password managers and policy changes on password strength.
Bergeron's research identified a second major improvement period starting in 2019, when password quality increased further. This phase was associated with broader adoption of password managers, machine-generated passwords, and stricter standards.
Flare researcher Andréanne Bergeron's analysis of leaked passwords from 2007 to 2025 found a notable improvement in password strength beginning around 2011. The shift was linked to stronger password policies and changing user behavior following major breach events.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.