Jakarta, ThedailyID — Kaspersky revealed that 68 percent of modern passwords can be hacked within a single day, despite many users already following basic password security rules.
The cybersecurity company reached the conclusion after analyzing 23 million leaked passwords collected between 2023 and 2026.
According to the study, many users still rely on predictable password patterns. The most common examples include passwords that start or end with numbers, contain birth years, or use keyboard sequences such as “1234” and “qwerty.”
Kaspersky warned that those patterns make passwords highly vulnerable to brute force attacks. In those attacks, hackers use automated software to test millions of combinations until they find the correct password.
The company found that 53 percent of compromised passwords ended with numbers, while 17 percent started with numbers. Another 12 percent included date-like number sequences between 1950 and 2030.
Meanwhile, around 3 percent contained keyboard patterns such as “1234,” “qwerty,” or reversed variations like “ytrewq.”
Alexey Antonov explained that cybercriminals often target predictable habits that users repeat when creating passwords.
“Bruteforce works systematically by trying every possible character combination until the correct password is found,” Antonov said.
“When attackers already know which characters users tend to favor, the time needed to crack a password decreases drastically,” he added.
Kaspersky also discovered that many people use emotional or trending words as password bases. One example is the word “Skibidi,” whose appearance in passwords reportedly increased 36 times between 2023 and 2026.
Positive words appeared more frequently than negative ones. Common examples included “love,” “magic,” “friend,” “angel,” and “star.” However, some users also used darker words such as “hell,” “devil,” and “nightmare.”
The company stressed that single-word passwords remain weak, even when users add numbers or symbols at the end.
Instead, experts recommend creating long passphrases that combine unrelated words, symbols, numbers, and intentional misspellings. Kaspersky also urged users to activate two-factor authentication, or 2FA, for stronger account protection.





