How do passwords get cracked?

Accounts are rarely broken into the way films show it. In practice a password is obtained in one of three ways. It is cracked: worked out by trying one candidate after another, usually against a database of password hashes stolen from a service. It is stolen: typed into a fake page or copied by malware. Or it is reused: attackers take a password from an earlier leak and try it on other services, counting on the owner having used it there too. The difference matters, because each is countered by something different. This article goes through the main methods and names what helps against each one.

Reused passwords from data leaks

Every year services are breached, and their user databases end up for sale or freely shared. Attackers take the pairs of email address and password from one leak and try them automatically on banks, mail providers, shops and social networks — an attack called credential stuffing. It involves no guessing at all, and it works for a simple reason: people reuse passwords. Even a strong password does not help here if it is the same one everywhere.

What helps: a different password for every account, so that a leak at one service opens nothing else.

Phishing

A phishing page is a copy of a real login page at a slightly different address, reached through a link in an email or a message that sounds urgent: a blocked account, a parcel, an invoice. Whatever you type there goes straight to the attacker. The length and randomness of the password make no difference, because you enter it yourself.

What helps: open sites from your own bookmarks rather than from links. Use a password manager: it offers to fill a password in only at the address it was saved for, so if it does not offer the saved password, check the address before typing it in by hand. And turn on two-factor authentication, which makes a stolen password insufficient on its own. One-time codes can be phished in the same way as the password, though. Passkeys and FIDO2 security keys cannot, because they answer only to the genuine site — the distinction that NIST calls phishing resistance.

Malware

Programs known as infostealers copy the passwords saved in a browser, together with session cookies, and send them off within seconds of being run, while keyloggers record what is typed. A stolen session cookie can let an attacker into an account that is already signed in, without the password and without the second factor. Such programs usually arrive in pirated software, fake updates and email attachments.

What helps: installing software only from its official source, keeping the system and the browser updated, and treating an unexpected attachment as hostile — none of which is a guarantee. If a device has been infected, act from another device that you know is clean: change the passwords, use each service's option to sign out of all sessions, and check that the recovery email, the phone number and the two-factor settings are still yours. Clean the infected device before you sign in on it again.

Guessing at the login form

Trying passwords directly against a website is slow: a well-built service delays, blocks or asks for a captcha after a few wrong attempts. That makes hammering a single account inefficient, so a common approach is the opposite one: a handful of the most common passwords — 123456, password, qwerty123 — tried against millions of accounts, which is called password spraying. Targeted guessing works the same way with personal details: the names of children and pets, birthdays, a favourite team, all easy to find on social media.

What helps: any password that is neither common nor built from facts about you — see how to create a strong password.

Cracking stolen hashes offline

A properly built service does not store passwords in readable form. It stores hashes — the output of a one-way function from which the password cannot be computed back. When such a database leaks, attackers test possible passwords: they compute the hashes of candidates on their own hardware and compare the results. No login form slows them down, and the speed depends on the hash function the service chose and on its settings. For fast, outdated functions such as MD5, a single modern graphics card tests tens of billions of candidates per second. Functions designed for storing passwords — Argon2id, or bcrypt in older systems — are deliberately slow and cut that rate by many orders of magnitude, which is why current recommendations name them.

Dictionary attacks

The candidates are not random. Cracking tools start with lists of real passwords from earlier leaks and with dictionaries of words and names, then apply rules that imitate human habits: a capital first letter, a year or an exclamation mark at the end, a letter replaced by a similar symbol. A password such as Summer2024! looks complex and is among the first candidates tried. Salting — adding a unique random value to each password before hashing — prevents attackers from using precomputed tables, known as rainbow tables, and from cracking all identical passwords at once, but it does not make a predictable password any less predictable.

Brute force

When the dictionaries are exhausted, what remains is trying every combination, and for a randomly generated password length is what decides the outcome. As an illustration, take a fast hash and a password in which every character is chosen independently, with equal probability, from the 94 printable ASCII characters, the space excluded. There are about 6 × 1015 such passwords of 8 characters; at ten billion guesses per second, trying them all takes about a week, and on average the right one turns up in half that time. For 12 characters, trying them all on the same hardware would take about 1.5 million years, and for 16 the figure is beyond any meaningful comparison. That is the whole argument for long random passwords: dictionaries are of little use against them, and under these assumptions trying every combination is not practical. Our strong password generator makes them in your browser and shows an entropy estimate for each one in bits.

What helps: a long password with no human pattern in it, which in practice means a generated one. You cannot control how a service stores your password, so assume the worst and choose one that resists guessing even when it is stored with a fast hash function.

Watching and asking

The oldest methods need no technology. A password is read over a shoulder, off a sticker on a monitor, or from a screen shared in a video call; or the attacker simply asks for it, posing as support staff or a colleague — what is called social engineering. No legitimate service will ever ask for your password by phone, email or chat.

What helps: never saying or sending a password to anyone, and not keeping it where others can see it.

What this adds up to

Different attacks are countered by different habits, and three of them do most of the work: a unique password for every account, generated rather than invented, with two-factor authentication on top — or a passkey instead of the password, where the service offers one. They do not cover everything — a stolen session, for one — which is why the advice on malware above matters as well. More articles are collected in the password guides.