Over two billion passwords were leaked by hackers in 2021

Passwords
Image Credit: Shutterstock (Image credit: Shutterstock)

Over the course of 2021, hackers managed to steal more than two billion passwords, a new report from ForgeRock has claimed. 

The company’s fourth annual breach report found that besides passwords, hackers have also been stealing people’s names, addresses, Social Security numbers, dates of birth, protected health information (PHI), and payment or banking details.

What’s more, the two billion is an increase of more than a third (35%), compared to just two years ago.

Most of the time, hackers sell the data on the black market, such as underground web forums and trading sites. While the passwords themselves often aren’t that expensive to purchase, they do open the gates for a number of potential attacks, from identity theft, to ransomware, and everything in between.

Two years ago, there had been more than 15 billion passwords on sale, on the dark web, the same report claims. 

“Usernames and passwords are the internet’s weakest link. The world has moved far beyond the point where a simple password can provide sufficient protection, and attackers know it. Spurred by the FIDO2 WebAuthn standard, the move to passwordless authentication is gaining momentum: it improves both security and ease of use for online access, while greatly diminishing the usefulness of stolen credentials by cybercriminals,” said ForgeRock CEO, Fran Rosch.

ForgeRock believes the future is passwordless, with biometric solutions (facial recognition, fingerprint scanners, and similar) being at the forefront. Others lean more towards multi-factor authentication as the best way to protect online accounts, as time-based keys and tokens prevent those with just the password from accessing other people’s accounts.

That being said, ForgeRock expects the passwordless authentication market to grow from $12.79 billion last year, to more than $53 billion by 2030. Whether or not that actually happens, remains to be seen. The password has been pronounced dead countless times before, yet somehow, it still prevails despite its shortcomings.

Via: VentureBeat

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
A digital representation of a lock
Gen Z and Millennial social media accounts are ripe for the taking and this doesn’t surprise me
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
password manager
I'm a security expert - here are my biggest tips for creating a secure password for work and home life to stay safe online
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
A hand laying out a password
Security attacks on password managers have soared
Latest in Security
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
Latest in News
Perplexity Squid Game Ad
New ad declares Squid Game's real winner is Perplexity AI
Frank Grimes confronts Homer Simpson in The Simpsons' Homer's Enemy episode
Disney+ adds a new continuous Simpsons stream, so you no longer have to spend ages choosing an episode
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good
Foldable iPhone
Apple’s first foldable iPhone could beat the Samsung Galaxy Z Fold 7 in one key way
Marvel Rivals
Marvel Rivals' next update will add two new hero skins for Iron Man and Spider-Man mains this week
Nvidia Isaac GROOT N1
“The age of generalist robotics is here" - Nvidia's latest GROOT AI model just took us another step closer to fully humanoid robots