Hackers can now crack complex passwords eight times faster than last year, according to researchers at the American cybersecurity company Hive Systems.
They also warn that a password made up only of numbers is the easiest to crack, even if it has more than 10 digits. A six-character password that mixes numbers with uppercase and lowercase letters can also be cracked almost instantly.
Experts attribute this jump to recent advances in technology.
“Now the time has come when passwords are no longer reliable,” said Alex Nette, CEO and co-founder of Hive Systems. He said the easy availability of artificial intelligence tools has given hackers unprecedented access to personal data. “Without additional protection, that data cannot be considered secure,” he added.
What the new research found
Hive Systems focused its recent research on new cases of password breaches. According to its findings, numeric passwords are the most vulnerable. Hackers were able to crack these codes quickly, even when they were 11 digits long.
The Daily Mail reported that hackers could crack four- to eight-character passwords almost instantly.
Researchers found it took only one second to crack a 12-character password and less than a week for an 18-character one.
It took attackers only 30 minutes to crack an 11-character password. But if a password included at least seven lowercase letters along with other character types, it would take roughly 480,000 years to decipher.
The most reliable passwords were those that combined numbers, symbols, and both upper- and lowercase letters. However, experts warn that if such mixed passwords are only four to seven characters long, they can still be cracked quickly. By contrast, a mixed 12-character password would take about 226 years to decrypt. Add six or more symbols to a password, and hackers would need roughly 26 trillion years to break it.

Can one password work for everything?
Jake Moore, an advisor at international cybersecurity company ESET, said using different passwords for each site is another key way to protect yourself from attackers.
“Cybercriminals roam the dark web in search of lists of compromised usernames and passwords,” he explained. Hackers then try those known passwords on other accounts belonging to the same user. “When people use the same password everywhere for years, or only change the last digit, they are essentially handing over the keys to their valuable data and financial accounts,” Moore said.
That’s why it’s important never to use the same password twice.
Moore recommends long, unique passwords that are protected by multi-factor authentication. That way, even if a hacker uncovers your password, they’ll still need your device, a time-based code, or biometric data to access the account.
Tips for creating a reliable password
- Choose an 18-character password that includes digits, symbols, lowercase letters, and uppercase letters.
- Use a password manager if you have trouble remembering long passwords.
- Don’t use the same password everywhere.
- Avoid memorable dates, personal facts, and names, such as your birthday or your dog’s name.
- Avoid numeric-only passwords — they’re the least secure.