Rising attacks make password hygiene more important than ever

passwords
(Image credit: italii Vodolazskyi / Shutterstock)

Credential stuffing attacks, in which attackers automate numerous attempts to compromise a large number of user accounts with stolen passwords, are rising exponentially.

New figures from Auth0 claim that despite credentials threats rising, the use identity management tools, or other security systems designed with minimizing the risk of attack often get deprioritized.

In the first 90 days of the year, Auth0 has found, credential stuffing took up 16.5% of all attempted login traffic on its platform. At the end of March, the figure peaked at more than 40%. The two industries bearing the brunt of these blows are travel & leisure, and retail. 

Approximately 15% of all attempts to register a new account, Auth0 has further discovered, can be attributed to bots. In the same timeframe of 90 days, Auth0 has seen more than 26,000 breached passwords every day. On the most peaceful of days, there was “only” 7,300 breached passwords, while the record-breaking February 9 saw more than 182,000.

There could be many reasons to deprioritize security measures, including budget constraints, lack of resourcing, or a lack of attention from the upper echelons of management. 

Password a "protective measure from the past"

Besides credential stuffing, which Auth0 claims is the most common threat these days, criminals will often go for fraudulent registration, multi-factor authentication bypass methods, as well as breached password usage.

For Duncan Godfrey, VP of Security Engineering at Auth0, businesses are part of the problem as failure to protect data is “industry-wide”. With criminals expanding their arsenal of automated tools by the hour, and security teams not having a proper horse for the race, the “humble password is a protective measure from the past,” he claims. 

In today’s world, relying on passwords for security is a risk in itself. 

“Despite ongoing guidance around proper password creation and repeated warnings against password reuse, consumers crave convenience and continue to use the easiest and most convenient path for application access,” said Shiv Ramji, Chief Product Officer at Auth0. 

“A passwordless future is largely being driven by two primary forces — security and convenience. Companies want to secure the vulnerabilities that come with passwords, and they also want to offer their users a better digital experience.”

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
A hand laying out a password
Security attacks on password managers have soared
password manager
I'm a security expert - here are my biggest tips for creating a secure password for work and home life to stay safe online
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
Hands typing on a keyboard surrounded by security icons
Infostealers on the rise: the latest concern for organizational defenses
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC