Specops Software

17 STATS1 REPORTS

All Statistics

Keyboard walks such as ‘qwerty’ are weak passwords used by millions of end users.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityEnd UsersWeak passwordsRisk

The most commonly used keyboard walk pattern was “Qwerty,” which appeared over 1 million times in a list of compromised passwords.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityCredentialsCommon passwordsRisk

88% of organisations still use passwords as their primary method of authentication.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
AuthenticationPassword SecurityCredentialsOrganizations

31.1 million breached passwords were over 16 characters in length.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityCredentialsData breachAuthentication

83% of compromised passwords satisfied the length and complexity requirements of regulatory password standards.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityRegulatory ComplianceComplexityData breach

Only 12% of organisations have moved away from using passwords as their primary method of authentication.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
AuthenticationPassword SecurityOrganizationsTechnology

Simple passwords like Pass@123 and P@ssw0rd, which meet basic Active Directory requirements, are frequently used, increasing the risk of password reuse.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityActive DirectoryCredentialsRisk

45% of organisations who only check for compromised passwords during expiry or reset events average only two checks for compromised passwords per year.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityBreach DetectionMonitoringOrganizations

Organisations using SaaS apps have an average of 47,750 passwords to manage.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
SaaSPassword SecurityManagementCredentials

Over 31 million of the breached passwords were over 16 characters in length.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityCredentialsData breachAuthentication

Only 50% of organisations scan for compromised passwords more than once a month.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityBreach DetectionMonitoringOrganizations

The most common base terms used in breached passwords were “password”, “admin”, and “welcome”.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityCredentialsCommon passwordsRisk

53% of people admit to using the same password across multiple accounts.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityCredentialsAccount securityRisk

The most common length for compromised passwords was 8 characters (212.5 million total).

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityCredentialsLengthCompromised

123456 was the most common compromised password found in a new list of breached cloud application credentials.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityCredentialsData breachAuthentication

After analysing 1.8 million breached administrator credentials, 40,000 admin portal accounts were found to be using ‘admin’ as a password.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityAdministrator AccountCredentialsRisk

Requiring an Active Directory password length of at least 13 characters would significantly reduce the risk of cloud application password reuse.

Specops Software2024 Specops Breached Password Report·Jan 1, 2025
Password SecurityActive DirectoryCredentialsRisk