Researchers analysed more than 19 billion leaked passwords.
Only 6% were unique (Cybernews, 2026).
The other 94% were either exact reuses of passwords already seen in earlier breaches, or small variations on common patterns.
That single finding explains most of how accounts get taken over.
Attackers do not need to crack anything. They just try passwords that already exist.
Here is what the data shows, and the one free fix that stops nearly all of it. 🔑
🎁 Compare Password Manager Trials →
🧾 Risultati principali in sintesi
| Misura | Figura | Fonte |
|---|---|---|
| Leaked passwords analysed | Over 19 billion | Cybernews (2026) |
| Share that were unique | 6% | Cybernews (2026) |
| People who reuse passwords | About 48% | Gitnux (2026) |
| Average times a password is reused | 14 | Gitnux (2026) |
| Bot traffic that is credential stuffing | 18% | Deepstrike (2026) |
| Breaches starting with stolen credentials | 22%, down from 31% | Verizon DBIR (2025) |
| MFA reduction in account compromise | 99.22% | Microsoft (2026) |
| Same, when password already leaked | 98.56% | Microsoft (2026) |

🔍 What the 19 Billion Tell Us
The scale of that analysis is what makes it convincing.
Nineteen billion passwords is not a survey. It is close to a census of what leaks.
🥧 Of 19 billion leaked passwords, how many were unique
What “not unique” actually means
Two categories, and both are exploitable.
Some were exact matches for passwords already exposed in earlier breaches.
Others were minor variations, like adding a number or changing a letter to a symbol.
Attackers test both, because the variation patterns are entirely predictable.
Why adding “1” at the end does not help
Password-guessing tools apply the same transformations you would.
Capitalise the first letter. Add a year. Swap “a” for “@”.
Those are the first things tried, not clever last resorts.
The reuse numbers behind it
About 48% of people reuse passwords across sites (Gitnux, 2026).
The average person reuses a password 14 times.
So one leak does not expose one account. It exposes fourteen.
🤖 How Credential Stuffing Works
This is the attack the reuse data enables, and it is depressingly simple.
| Fare un passo | What happens |
|---|---|
| 1 | A site is breached, credentials leak |
| 2 | Lists are compiled and traded |
| 3 | Bots test them against other services |
| 4 | A small percentage work |
| 5 | Those accounts are drained or resold |
There is no cracking, no cleverness and no targeting.
It is automated guessing that works because people reuse passwords.
The volume involved
Around 18% of observed bot traffic is credential stuffing (Deepstrike, 2026).
At single sign-on providers, roughly 19% of daily authentication attempts are stuffing attempts.
Nearly one login attempt in five is an attack.
Why a low success rate is enough
Success rates per attempt are tiny, often well under 1%.
That does not matter when you can attempt millions of logins cheaply.
Automation turns a bad success rate into a reliable business.
What attackers do with the accounts
It depends what the account holds.
Stored payment details, loyalty points, or access to a work system.
Often the account is simply resold, because a verified working login has value.
✅ The Fix, and How Well It Works
Multi-factor authentication is unusually well evidenced.
Microsoft studied account compromise across a very large population.
MFA reduced the risk of compromise by 99.22% (Microsoft, 2026).
And here is the number that matters most for this article.
📊 Reduction in account compromise with MFA
The second bar is the important one
Even when the password had already leaked, MFA prevented 98.56% of compromises.
That means a stolen password becomes almost worthless on its own.
Credential stuffing depends entirely on the password being sufficient. MFA removes that.
Other supporting figures
MFA blocks around 99.9% of automated attacks.
It prevents roughly 96% of bulk phishing and 76% of targeted attacks (Deepstrike, 2026).
Notice the drop for targeted attacks, which is honest and important.
⚠️ Not All MFA Is Equal
This is where most articles stop, and where the useful detail begins.
“MFA” covers everything from a texted code to a hardware key.
Attackers have learned to defeat the weaker forms.
| Method | Forza | Main weakness |
|---|---|---|
| SMS code | Weakest | SIM swapping, interception |
| Email code | Weak | Only as safe as the email account |
| Authenticator app code | Bene | Phishable if you type it in |
| Push approval | Bene | Approval fatigue |
| Passkey or hardware key | Strongest | Device loss, needs backup |
The bottom row is described as phishing-resistant for a specific reason.
A passkey is bound to the real website, so it cannot be handed to a fake one.
Why SMS is still worth using
SMS is the weakest form, and it is still enormously better than nothing.
The gap between no MFA and SMS MFA is far larger than the gap between SMS and a passkey.
Do not let the search for the best option stop you enabling any option.
The approval-fatigue problem
Push notifications ask you to approve a login with one tap.
Attackers send repeated requests until someone taps to make it stop.
If you get an approval prompt you did not trigger, deny it and change that password.
📉 One Piece of Good News
The trend is actually improving, which rarely gets reported.
Verizon found stolen credentials were the initial access route in 22% of breaches, down from 31% (Verizon, 2025).
That is a meaningful fall in a single reporting period.
Why it is falling
MFA adoption has risen sharply across major platforms.
Many services now enable it by default rather than offering it.
Passkeys have also started replacing passwords entirely in some places.
What it does not mean
Credentials are still the second most common way in.
A fall from 31% to 22% is progress, not resolution.
The attack still works on everyone who has not enabled MFA.
📉 The Trend, Charted
The Verizon figure is worth seeing rather than just reading.
📊 Breaches beginning with stolen credentials
Nine points in one reporting period is a substantial move.
This is one of the few security metrics genuinely improving.
Why it is worth noticing
Security coverage is relentlessly negative, which makes real progress invisible.
Defences do sometimes work, and MFA is the clearest current example.
Reporting only the bad numbers makes people fatalistic, which helps nobody.
The remaining 22%
Credentials are still the second most common way attackers get in.
The improvement came from people who enabled MFA.
Those who have not are still fully exposed to the same attack.
🔐 What to Actually Do
Five steps, in order of value per minute spent.
| Fare un passo | Time | Effect |
|---|---|---|
| 1. Enable MFA on email first | 3 minuti | Email resets everything else |
| 2. Enable MFA on banking and work | 10 min | Highest-value accounts |
| 3. Install a password manager | 20 min | Makes unique passwords possible |
| 4. Change reused passwords on key accounts | 30 min | Breaks the reuse chain |
| 5. Check your email against breach databases | 2 minuti | Tells you what already leaked |
Step one matters more than the rest combined.
Why email comes first
Your email account can reset the password on almost every other service.
An attacker who controls it controls everything downstream.
Securing email is not one account. It is the master key.
Why a password manager is the enabler
Nobody can remember 100 unique passwords. That is not a discipline failure.
A manager removes the need to remember, which removes the reason to reuse.
It converts an impossible habit into a solved problem.
You do not need to change everything
Changing 200 passwords is a project nobody finishes.
Change the ones that matter: email, banking, work, anything holding payment details.
Let the rest be replaced gradually as you log in over time.
🔑 Passkeys: What Is Actually Changing
The longer-term answer is removing passwords entirely.
Passkeys are already available on major platforms, and they work differently.
| Parola d'ordine | Passkey | |
|---|---|---|
| What you remember | A secret | Niente |
| Stored on the server | A hash of your secret | A public key only |
| Value if the server is breached | High to attackers | Useless to attackers |
| Can be phished | SÌ | No — bound to the real site |
| Can be reused across sites | Yes, and people do | Not possible |
The third row is the one that ends this whole article’s problem.
A breached server holding passkeys leaks nothing an attacker can use.
Why phishing stops working
A passkey is cryptographically tied to the real website address.
Present it with a lookalike domain and it simply will not respond.
You cannot be tricked into handing it over, because there is nothing to hand over.
The practical caveats
Passkeys are tied to devices and accounts, so losing a device matters.
Set up recovery before you rely on them.
And support is still uneven, so passwords will exist alongside them for years.
What to do now
Enable passkeys where offered, especially on email and major accounts.
Keep MFA on everything else.
The transition will be gradual, and both will coexist for a long time.
🧪 Checking What Has Already Leaked
Given 19 billion leaked passwords exist, assume some of yours are among them.
Free breach-checking services let you search by email address.
How to read the result
A hit does not mean an account is currently compromised.
It means credentials from that service appeared in a breach at some point.
Treat any password used at a breached service as public.
Set up alerts rather than checking once
Breaches keep happening, so a single check has a short shelf life.
Most breach-notification services will email you when your address appears in a new leak.
That turns a one-off task into an ongoing safeguard for no extra effort.
What to do about old breaches
If you reused that password anywhere, change it there too.
That is the chain credential stuffing exploits.
One breach plus reuse equals many compromised accounts.
🧩 Why Password Rules Made Things Worse
For twenty years, sites demanded complexity and frequent changes.
That advice has now been reversed by the standards bodies that issued it.
| Old rule | What it caused | Current guidance |
|---|---|---|
| Force a change every 90 days | Predictable increments | Change only on suspicion |
| Require symbols and mixed case | Same word, decorated | Favour length instead |
| Ban password managers | Reuse and sticky notes | Encourage managers |
| Security questions | Answers are publicly findable | Avoid or randomise |
The first row is the clearest own goal.
Forced rotation produced Summer2024, then Summer2025, then Autumn2025.
Attackers know that pattern better than most users do.
Why length beats complexity
Guessing difficulty rises far faster with length than with symbol variety.
A long passphrase of ordinary words is stronger and easier to remember.
Complexity requirements mostly produced predictable substitutions instead.
Why the old advice persisted
It was written before large-scale breach data existed.
Once researchers could examine billions of real passwords, the assumptions failed (Bright Defense, 2026).
Guidance changed. Corporate policies, in many places, did not.
🏢 The Same Problem at Work
Everything above applies to organisations, at larger scale.
Stolen credentials remain a leading route into company systems (Verizon, 2025).
Nostro breach cost analysis shows what follows when that succeeds.
Why company MFA sometimes fails
Usually because it is optional, or applied only to some systems.
Attackers find the one service without it.
Partial MFA is much weaker than it appears on a compliance checklist.
Shared accounts are the hidden weakness
Most teams have a few logins shared between several people.
Social accounts, a billing portal, a supplier system.
Shared passwords cannot be rotated when one person leaves, so usually they never are.
A team password manager solves this properly, by sharing access rather than the secret itself.
The joiner and leaver problem
Accounts belonging to people who left often keep working.
Those accounts rarely have MFA reviewed and nobody notices unusual logins.
They are among the most attractive targets in any organisation.
🧰 Choosing a Password Manager
Since the manager is what makes unique passwords possible, choosing one matters.
| Cosa controllare | Perché |
|---|---|
| Zero-knowledge encryption | Provider cannot read your vault |
| Independent security audits | Claims verified by outsiders |
| Breach history and response | How they behaved when tested |
| Export your data easily | You are not locked in |
| Works on all your devices | Unused on mobile means unused |
| Emergency access or recovery | What happens if you forget the master password |
The first row is the essential one.
Zero-knowledge means your vault is encrypted before it leaves your device.
Even a breach of the provider yields encrypted data they cannot decrypt.
The obvious objection
People ask whether storing everything in one place is risky.
It is a fair question with a clear answer.
The alternative is reusing one password everywhere, which is a single point of failure with no encryption at all.
The browser-built-in option
Browsers now include competent password managers, free.
They are considerably better than reuse, and the friction is near zero.
If a dedicated manager feels like too much, start there rather than doing nothing.
The master password
This is the one you must remember, so make it a long passphrase.
Several unrelated words beat a short complex string.
And set up recovery before you need it, not after.
🔬 Quanto è affidabile questa ricerca?
| Fonte | Forza | Caveat |
|---|---|---|
| 19-billion password analysis | Enormous sample | Only covers leaked passwords |
| Microsoft MFA study | Very large, real accounts | One platform |
| Verizon DBIR | Long-running, consistent | Reported incidents only |
| Vendor password surveys | Pratico | They sell managers |
The first row carries a subtle bias worth naming.
Leaked passwords are not a random sample of all passwords.
They come from breached services, which may skew toward weaker security.
The true reuse rate across all passwords could be somewhat lower than 94%.
Why the conclusion survives anyway
Even at a much lower reuse rate, credential stuffing still works.
And the MFA evidence is independent of the reuse figure entirely.
The recommendation does not depend on the most dramatic statistic being exact.
🚫 Cosa non ti dicono questi dati
It does not measure your personal risk. That depends on your own habits.
Leaked passwords are a biased sample. They come from breached services.
MFA figures come largely from one platform. Others may differ.
It cannot see unreported breaches. Those never enter the statistics.
Some research is vendor-funded. Password managers benefit from these findings.
🏁 La versione breve
Of 19 billion leaked passwords, only 6% were unique (Cybernews, 2026).
About 48% of people reuse passwords, on average 14 times each.
That is why credential stuffing works, and why 18% of bot traffic is exactly that.
MFA cut account compromise by 99.22%, and by 98.56% even when the password had already leaked (Microsoft, 2026).
So the single highest-value action is enabling MFA on your email account.
Then a password manager, so unique passwords stop requiring memory.
Not all MFA is equal, but any MFA beats none by an enormous margin.
One last thing worth saying, because this topic invites shame.
Reusing passwords is not carelessness. Remembering a hundred unique strings was never possible.
The failure was in the advice, which demanded something human memory cannot do.
Password managers and passkeys fix the design, not the person. 🔑
❓ Domande frequenti
How many people reuse passwords?
About 48%, and the average person reuses a password 14 times across accounts (Gitnux, 2026).
What did the 19 billion password study find?
Only 6% were unique. The rest were exact reuses or predictable variations (Cybernews, 2026).
Does adding a number to my password help?
Very little. Guessing tools apply exactly those transformations first, not last.
What is credential stuffing?
Automated testing of leaked username and password pairs against other services. Around 18% of bot traffic is this attack.
How effective is MFA?
It reduced account compromise by 99.22%, and by 98.56% even when the password had already leaked (Microsoft, 2026).
Is SMS-based MFA worth using?
Yes. It is the weakest form, but the gap between no MFA and SMS MFA is far larger than between SMS and a passkey.
Which account should I secure first?
Email. It can reset the password on nearly every other service, which makes it the master key.
Do I need to change every password?
No. Change email, banking, work and anything holding payment details. Replace the rest gradually.
Are passkeys worth switching to?
Yes where offered. A breached server holding passkeys leaks nothing usable, and they cannot be phished because they are bound to the real site.
Should I still change passwords every 90 days?
No. Forced rotation produces predictable increments like Summer2024 then Summer2025. Current guidance is to change on suspicion of compromise.
Is a password manager safe to trust?
Look for zero-knowledge encryption, which means your vault is encrypted before it leaves your device. The alternative — one reused password — is a single point of failure with no encryption at all.
What if I forget my master password?
Set up recovery before you need it. Zero-knowledge providers genuinely cannot reset it for you, which is the point.
Is the problem getting better?
Somewhat. Stolen credentials fell from 31% to 22% of breach entry points as MFA adoption rose (Verizon, 2025).
📚 Riferimenti
Cybernews. (2026). Analysis of 19 billion leaked passwords, cited in Gitnux password reuse statistics. Retrieved August 8, 2026, from https://gitnux.org/password-reuse-statistics/
Microsoft. (2026). How effective is multifactor authentication at deterring cyberattacks? Retrieved August 8, 2026, from https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/MFA-Microsoft-Research-Paper-update.pdf
Deepstrike. (2026). Credential stuffing statistics: ATO, bots, APIs and leaks. Recuperato l'8 agosto 2026, da https://deepstrike.io/blog/credential-stuffing-statistics
Verizon. (2025). Data breach investigations report, cited in Deepstrike password statistics. Retrieved August 8, 2026, from https://deepstrike.io/blog/password-statistics-2025
Bright Defense. (2026). 160+ password statistics. Recuperato l'8 agosto 2026, da https://www.brightdefense.com/resources/password-statistics/
Letture correlate su questo sito
Nostro breach cost analysis shows what happens after credentials are stolen. See also our public Wi-Fi research, where fake login portals harvest exactly these credentials, and the Elenco degli utenti che effettuano la prova gratuita for password manager trials.
Informazioni su questa analisi
The 94% reuse figure comes from leaked passwords, which are not a random sample of all passwords — that limitation is stated rather than hidden. The MFA recommendation does not depend on that figure being exact, since the Microsoft evidence is independent of it. Figures were checked on August 8, 2026.
-
Password Reuse: The Numbers Behind Most Breaches - Settembre 9, 2026 -
Is Tube Magic Legit? Checking the Claims Against the Evidence - Settembre 9, 2026 -
What YouTube AI Tools Really Cost: A Side-by-Side Price Table - Settembre 8, 2026
