Almost any 8-character password can now be cracked within a day

May 22, 2026  10:31

Even relatively “long” 8-character passwords can be broken by attackers in as little as 24 hours on average today. The situation with 10-character passwords is only slightly better. This is according to research by experts from Kaspersky.

What the study found

According to Kaspersky, modern computing power and attack algorithms allow hackers to try password combinations at extremely high speed. Key findings include:

8-character passwords — virtually all can be cracked within 24 hours. 10-character passwords — around 90% can also be compromised within the same time frame.

In general, the shorter the password, the faster it is broken. However, even increasing length to 10 characters does not provide strong protection if the password consists of simple or predictable patterns.

Why password cracking has become so fast

Researchers highlight two main reasons:

Increase in hardware performanceNew graphics cards such as the RTX 5090 provide roughly 30% faster brute-force performance compared to the RTX 4090. GPUs are particularly efficient at password-guessing computations. Smarter algorithms and human habitsPeople rarely use truly random passwords. Instead, passwords often include: dates and years (such as “2025” or “1998”); names, words, and simple variations; common sequences and patterns.

Attack algorithms take advantage of these habits and prioritize the most likely combinations first. Even when special characters are used, patterns remain predictable: in every tenth password containing symbols, the “@” character appears most often, followed by the dot (.) and the exclamation mark (!).

What this means in practice

Many services already prevent the use of very short passwords (4–6 characters). However, the study shows that simply increasing length to 8–10 characters is no longer enough if the password is predictable.

How to protect yourself

Experts recommend:

Using passwords at least 12–16 characters long; Combining uppercase and lowercase letters, numbers, and special characters; Using password managers to generate truly random and long passwords; Enabling two-factor authentication (2FA) wherever possible. In brief

According to Kaspersky research, modern GPU power and advanced algorithms make it possible to crack almost any 8-character password within a day, while around 90% of 10-character passwords can also be broken in that timeframe. The main issue is not only length but also predictable human behavior. For strong protection today, experts recommend using 12–16 character passwords generated by a password manager and enabling two-factor authentication.

Follow NEWS.am Tech on Facebook and Twitter