About this module
Attackers do not need a clever exploit when a password is short, reused, or already leaked. This lesson shows how bots test accounts nonstop, how brute force and dictionary attacks work, and why an eight-character password can fall in less than six hours. Learners also see how credential stuffing uses one leaked password against banking, email, and work systems. The self-check is plain: fewer than twelve characters, common patterns, reuse, or personal details all raise the risk. The fix is just as plain: longer unique passwords, MFA, and better password management.
Key takeaways
Every day billions of login attempts hit websites, banks, and corporate systems. A password stands between attackers and your most sensitive data.
Yet most people treat passwords as an afterthought. That stops today.
The scope is staggering. Right now, automated bots are probing millions of accounts every second across the globe.
No organisation and no employee is too small to be targeted. This is not theoretical — it is constant.
Eighty-one percent. That is the share of confirmed data breaches involving weak or stolen passwords, according to Verizon's Data Breach Investigations Report.
Nearly every major attack starts with a compromised credential. Brute force attacks try every possible combination of characters until they find the right one.
Modern graphics cards test hundreds of billions of combinations per second. A short or simple password offers almost no resistance.
Here is how fast an eight-character password falls: less than six hours using modern hardware. Shorter passwords collapse in seconds.
Only long, random strings push cracking time into decades or centuries. Dictionary attacks go further — trying every known word, common substitutions like p-at-zero-s-s-w-zero-r-d, and millions of previously leaked passwords.
If your password follows any recognisable pattern, attackers already have it on their lists. When your password surfaces in a data breach, automated bots immediately test it across thousands of other websites.
This is called credential stuffing. One compromised account can unlock banking, email, and work systems all at once.
How do you know if your password is weak? Four clear signs: it is under twelve characters, it contains common words or patterns, it has been reused across multiple sites, or it includes personal details like a birthday or name.
Any one of these puts you at serious risk. Year after year the most common passwords remain shockingly predictable.
One-two-three-four-five-six, 'password', and 'qwerty' top the global charts every single year. Two thirds of people reuse passwords across accounts, and attackers count on exactly that.
What does a successful password attack actually cost? In 2024, the average data breach cost organisations four-point-eight-eight million dollars — spanning regulatory fines, reputational harm, lost customers, and months of costly recovery.
Three numbers capture the full picture. Four-point-eight-eight million dollars — the average breach cost in 2024.
Twenty-four billion — stolen credentials on the dark web. Less than six hours — the time to crack an eight-character password.
Weak passwords are expensive. Here is the encouraging part: fixing your passwords is not complicated.
A few targeted changes — length, uniqueness, and multi-factor authentication — dramatically reduce your attack surface. The next lessons show you exactly how.
You now understand why weak passwords are the number-one entry point for attackers. In the next lesson, you will learn how to create passwords that are both strong and memorable.
See you there.



