Let's start with a confession. Somewhere in the world right now, a significant number of people are logged into important accounts with the password "123456." Over 7.6 million of them used that exact combination in passwords leaked in 2025 alone. It has been the world's most common password for six of the past seven years running.
If your first instinct is to think "well, I'd never do that," hold that thought. Because the real story of why passwords fail is considerably more interesting — and considerably more forgiving — than it first appears.
The scale of the problem
In 2025, two billion passwords were leaked in data breaches. Two billion. That is not a typo and it is not a rounding error. It works out to roughly 63 passwords exposed every second, all year, without pause.
Of the nineteen billion passwords analysed by security researchers in a single study, 94% were either reused across multiple accounts or were duplicates of passwords used elsewhere. Just 6% were genuinely unique. The average person reuses the same password across thirteen different accounts. And 80% of successful hacking attacks on companies in 2025 traced their entry point back to a weak or reused credential.
These numbers sound like an indictment of human laziness. But here is the thing: they are not. They are an indictment of a system that has been designed around an impossible expectation.
The system was never really designed for humans
Think about what we actually ask people to do with passwords.
The average person now manages somewhere between 70 and 100 online accounts. Each one wants a password. Many want that password to contain uppercase letters, lowercase letters, numbers, and at least one symbol. Several insist the password cannot be the same as any of your last ten passwords. Some require you to change it every 90 days. A few have told you it cannot contain your name, your birthday, or any real word from the dictionary.
What this produces, in practice, is not a hundred strong unique passwords. It produces a handful of passwords that people cycle through across most of their accounts, with slight variations that follow a completely predictable pattern. Password! becomes Password1 becomes Password1! becomes Password1!! and so on through each enforced change, while the underlying word stays the same.
Security researchers have known for years that this approach does not make people safer. It makes them less safe while making them feel more secure — which is arguably worse. The UK's National Cyber Security Centre, the US-based NIST standards body, and every other credible authority in the field has quietly abandoned the old complexity-and-change guidance. But the systems built around that old guidance are still everywhere, still demanding you capitalise something and add a symbol at the end.
The thing that actually matters: uniqueness
Here is the most important sentence in this article: a password that is used on more than one site is already compromised the moment any of those sites suffers a data breach.
This is called credential stuffing, and it is how the vast majority of account takeovers actually happen. Not by a criminal sitting at a keyboard guessing your password. By an automated system trying a list of email and password combinations — obtained from breached databases — across hundreds of websites simultaneously. If your email address and the password you use for a forum you signed up to in 2017 appear in a leaked database, that combination is being tried against your bank, your email, your shopping accounts, and anywhere else criminals think it might work.
Verizon's 2025 breach research found that 22% of all investigated breaches began with exactly this method — stolen credentials from one place being reused somewhere else. The password that was breached might not have been yours. It might have been a company's entire user database. But if your combination was in it, and you used it elsewhere, the breach that happened to someone else became a breach that happened to you.
The good news hidden in the bad statistics
Here is something the breach statistics rarely mention: passwords are getting better. Very slowly, but measurably.
Analysis of three massive breach databases across fifteen years shows that the proportion of passwords shorter than eight characters has fallen from 33% in 2009 to 10% in 2024. The proportion longer than sixteen characters has risen from 0.85% to almost 7%. People are, gradually, learning.
The other hopeful number: haveibeenpwned.com — Troy Hunt's free service that lets you check whether your email address appears in known breaches — has been visited by hundreds of millions of people and is now integrated into password managers and browsers worldwide. The culture around password security, while still imperfect, is meaningfully better than it was a decade ago.
The problem is that the threats have got better faster than the defences.
What does this mean for me?
Check your email address at haveibeenpwned.com. It is free, takes thirty seconds, and tells you whether your credentials have appeared in known breaches. If they have, change the relevant passwords.
The single most important habit: never use the same password on more than one account. Even if you only apply this rule to your email, your bank, and your main social media accounts, you will have significantly reduced your exposure to the credential stuffing attacks that cause the majority of real-world account takeovers.
Ignore the complexity theatre. A long password made of three or four random words — the NCSC recommends this approach — is stronger and more memorable than a short password full of symbols. "PurpleKettleMondayRiver" is genuinely harder to crack than "P@ssw0rd1!"
Next Friday: we look at what a good password actually looks like in 2026 — and why everything your school IT teacher told you about changing it every three months was well-intentioned but wrong.
🧠 The Human Factor
| Technology involved | Credential stuffing attacks, breach databases, and the password complexity requirements that inadvertently make people less safe |
| Root cause | Humans have been asked to manage an impossible number of unique passwords without the tools to do so — the predictable result is reuse, which attackers systematically exploit |
| What was at risk | Every account that shares a password with any other account — when one falls, all of them are at risk |
| Prevention | Unique passwords for every account; checking haveibeenpwned.com; choosing length over complexity |
References and sources
- NCSC: Three random words password guidance — ncsc.gov.uk
- Verizon: Data Breach Investigations Report 2025 — verizon.com
- NordPass: Most Common Passwords 2025 — nordpass.com
- Cybernews: 19 billion password analysis (April 2024–April 2025)
- haveibeenpwned.com — Troy Hunt