Even relatively “long” 8-character passwords can be broken by attackers in as little as 24 hours on average today. The situation with 10-character passwords is only slightly better. This is according to research by experts from Kaspersky.
According to Kaspersky, modern computing power and attack algorithms allow hackers to try password combinations at extremely high speed. Key findings include:
In general, the shorter the password, the faster it is broken. However, even increasing length to 10 characters does not provide strong protection if the password consists of simple or predictable patterns.
Researchers highlight two main reasons:
Attack algorithms take advantage of these habits and prioritize the most likely combinations first. Even when special characters are used, patterns remain predictable: in every tenth password containing symbols, the “@” character appears most often, followed by the dot (.) and the exclamation mark (!).
Many services already prevent the use of very short passwords (4–6 characters). However, the study shows that simply increasing length to 8–10 characters is no longer enough if the password is predictable.
Experts recommend:
According to Kaspersky research, modern GPU power and advanced algorithms make it possible to crack almost any 8-character password within a day, while around 90% of 10-character passwords can also be broken in that timeframe. The main issue is not only length but also predictable human behavior. For strong protection today, experts recommend using 12–16 character passwords generated by a password manager and enabling two-factor authentication.
month
week
day