60% of leaked passwords crack in under an hour

Passwords continue to be one of the most vulnerable points in digital security.
A Kaspersky analysis found that 68% of leaked passwords can be cracked in less than a day.
Sixty-eight percent of passwords leaked between 2023 and 2026 can be cracked in less than a day, according to an analysis conducted by Kaspersky on 231 million unique passwords exposed in major data breaches.
The study found that 60% can be cracked in approximately one hour using automated attacks.
Researchers identified that a large share of compromised passwords still follows predictable patterns, particularly in the use of numbers and symbols. Among the cases analyzed, 53% of passwords end with digits, 17% begin with numbers, and nearly 12% include sequences related to dates between 1950 and 2030.
Repetitive patterns in passwords.
The report also notes that many passwords use common combinations such as “1234,” keyboard sequences like “qwerty,” or repeated symbols.
Among passwords containing a single symbol, the most common is “@,” present in 10% of the analyzed cases.
According to Alexey Antonov, Head of Data Science at Kaspersky, the use of predictable patterns facilitates brute-force attacks and reduces the time needed to access compromised accounts:
“Brute-force attacks systematically test all possible combinations until they find the correct one. If cybercriminals know the most common patterns, the time needed to crack a password is drastically reduced. To avoid this, the best approach is to use password generators that create random combinations of letters, numbers, and symbols”.
Common words and trends.
The analysis also found that many people continue to use common words or terms associated with emotions and trends as part of their passwords. Among the most repeated terms are positive words such as:
“love”,
“magic”,
“friend”,
“team”,
“angel”,
“star”,
“eden”,
as well as other expressions such as:
“hell”,
“devil”,
“nightmare”,
“scar”.
According to Kaspersky, using a single word as a password, even when combined with numbers or symbols, remains vulnerable to automated attacks. Security experts recommend building random combinations using unrelated words together with numbers and symbols.
Antonov said:
“Using a single word as a password, even by adding a number or symbol, remains a weak option. It is a pattern that is too predictable. The best approach is to create passphrases that combine several unrelated words, incorporating numbers, symbols, and even small intentional variations. The longer, more random, and more unpredictable it is, the harder it will be to crack. In addition, it is essential to enable two-factor authentication whenever possible”.
Length is no longer enough.
Although longer passwords remain harder to break, the study concludes that length no longer guarantees sufficient protection if repetitive patterns are present. According to the analyzed data, more than 20% of 15-character passwords can be cracked in less than one minute using advanced AI-based algorithms.
Kaspersky’s calculations were conducted using an RTX 5090 GPU and the MD5 algorithm. According to the company, the use of multiple GPUs can significantly accelerate these cracking processes.
Security experts currently recommend using unique passwords longer than 16 characters, combining letters, numbers, and symbols without repetitive patterns. They also suggest using password managers and two-factor authentication to strengthen the protection of digital accounts.
The analysis is based on information from the Kaspersky Digital Footprint Intelligence service.

