logo

Password reuse is rampant: nearly half of observed user logins are compromised

ID: 907bde81-e7f2-518c-9fb6-bbed83605f06

STIX ID: report--907bde81-e7f2-518c-9fb6-bbed83605f06

Feed Name: Cloudflare Blog

Date Published: 2025-03-17

Date Updated: 2026-04-27

Author: Radwa Radwan

...
...

Cloudflare reports that password reuse is fueling large-scale credential-stuffing: 41% of successful human logins and 52% of all authentication attempts involve leaked passwords, with 95% of leaked-password attempts driven by bots. WordPress sites are heavily targeted, where 76% of leaked-password login attempts succeed (48% bot-driven), while only 5% are denied. The report urges deploying MFA, rate limiting, bot management, and leaked-credential detection to mitigate account takeover risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.