Skip to main content
HomeTopicsCredentials

Credentials

We've curated 136 cybersecurity statistics about credentials to help you understand how password management, multi-factor authentication, and the rise of phishing attacks are shaping the security landscape in 2025.

Showing 121-136 of 136 results

Based on Cloudflare's observed traffic between September - November 2024, 41% of successful logins across websites protected by Cloudflare involve compromised passwords.

Cloudflare3/17/2025
PasswordsLogin attempt

76% of leaked password login attempts for websites built on WordPress are successful.

Cloudflare3/17/2025
PasswordsLogin attempt

Approximately 41% of successful human authentication attempts involve leaked credentials.

Cloudflare3/17/2025
PasswordsLogin attempt

The most commonly used keyboard walk pattern was “Qwerty,” which appeared over 1 million times in a list of compromised passwords.

Specops Software1/1/2025
Password SecurityCommon passwords

88% of organisations still use passwords as their primary method of authentication.

Specops Software1/1/2025
AuthenticationPassword Security

31.1 million breached passwords were over 16 characters in length.

Specops Software1/1/2025
Password SecurityData breach

Simple passwords like Pass@123 and P@ssw0rd, which meet basic Active Directory requirements, are frequently used, increasing the risk of password reuse.

Specops Software1/1/2025
Password SecurityActive Directory

Organisations using SaaS apps have an average of 47,750 passwords to manage.

Specops Software1/1/2025
SaaSPassword Security

Over 31 million of the breached passwords were over 16 characters in length.

Specops Software1/1/2025
Password SecurityData breach

The most common base terms used in breached passwords were “password”, “admin”, and “welcome”.

Specops Software1/1/2025
Password SecurityCommon passwords

53% of people admit to using the same password across multiple accounts.

Specops Software1/1/2025
Password SecurityAccount security

The most common length for compromised passwords was 8 characters (212.5 million total).

Specops Software1/1/2025
Password SecurityLength

123456 was the most common compromised password found in a new list of breached cloud application credentials.

Specops Software1/1/2025
Password SecurityData breach

12% of respondents' organisations experienced a material privacy breach in the past 12 months.

ISACA1/1/2025
PrivacyQualifications

After analysing 1.8 million breached administrator credentials, 40,000 admin portal accounts were found to be using ‘admin’ as a password.

Specops Software1/1/2025
Password SecurityAdministrator Account

Requiring an Active Directory password length of at least 13 characters would significantly reduce the risk of cloud application password reuse.

Specops Software1/1/2025
Password SecurityActive Directory