SME Cybersecurity | Helping Keep UK SMEs CYBERSafe Daily » PASSWORD SECURITY: Experts Reveal Top Password Mistakes Driving Data Breaches in 2025

PASSWORD SECURITY: Experts Reveal Top Password Mistakes Driving Data Breaches in 2025

Password Security
Image Credit: Mohamed Hassan from Pixabay

Helping Keep Small Business CYBERSafe!
Gibraltar: Friday 23 May 2025 at 10:00 CET

PASSWORD SECURITY: Experts Reveal Top Password Mistakes Driving Data Breaches in 2025
By: Iain FraserCybersecurity Journalist
Published in Collaboration with: Nord VPN
SMECyberInsights.co.uk – First for SME Cybersecurity
#SMECyberInsights #SMECyberSecurity #SMECyberAwareness #CyberSafe #SME #SmallBusiness

Poor password practices continue to be the Achilles’ heel of cybersecurity, with over 80% of data breaches linked to compromised credentials, according to a new analysis by web hosting provider Hostinger.

The company’s security team conducted an extensive investigation into thousands of leaked password datasets, applying machine learning and behavioural analysis techniques to understand why many users still create passwords that offer minimal protection.

Critical Password Vulnerabilities Identified

“Many people assume they’re fully protected once they’ve set up a strong password, but security is an ongoing process,” explains Hostinger’s cybersecurity team. “New threats emerge constantly, and staying safe requires regular attention to your security practices.”

The research identified four primary password mistakes that consistently leave users vulnerable:

1. Inadequate Password Length

More than one-fifth (21.7%) of analysed passwords contained fewer than eight characters—all of which were instantly crackable in security tests. Despite the well-documented risks, many users continue to prioritize convenience over security by creating short passwords that are easier to type and remember.

Security experts recommend passwords of at least 12 characters, ideally based on memorable phrases or sentences.

2. Predictable “Unique” Patterns

Many users believe they’ve created secure passwords by using seemingly unique combinations like “minebluecar67.” However, Hostinger’s analysis revealed these formats follow predictable low-entropy patterns that sophisticated cracking tools can easily decipher.

To create truly secure passwords, cybersecurity professionals advise using a mix of uppercase and lowercase letters, numbers, and special characters while avoiding common words or predictable patterns.

3. The Length Misconception

The research uncovered a concerning trend: even passwords exceeding 20 characters had a 13% crack rate, making them nearly as vulnerable as much shorter options. This contradicts the common belief that longer passwords are automatically more secure.

“Length alone isn’t enough,” notes the report. “Passwords with repetitive elements like ‘aaaaaaa’ or ‘123123123’ significantly compromise security regardless of character count.”

4. Continued Use of Known Compromised Passwords

Perhaps most alarmingly, many users continue using passwords that appear in the top 10 million leaked password lists. The study identified 475 passwords that matched high-frequency entries from global breach databases.

This occurs because users often remain unaware their credentials have been compromised or continue reusing familiar passwords out of habit.

Protecting Your Digital Assets

Cybersecurity experts recommend regularly checking credentials through services like “Have I Been Pwned” and implementing two-factor authentication (2FA) wherever possible.

“Security-related settings should be maintained over time to ensure they still reflect your needs and provide the right level of protection,” emphasizes Hostinger’s security team.

As data breaches continue affecting businesses of all sizes, SMEs are particularly encouraged to review their password policies and implement comprehensive security awareness training for all staff members.

What is a VPN & Does my SME Need one? A VPN is a Virtual Private Network a method of securing your communications credentials. When it comes to Small and Medium-sized enterprises (SMEs), the choice of VPNs can significantly impact the security and efficiency of their operations.

The NordVPN service allows you to connect to 5600+ servers in 60+ countries. It secures your Internet data with military-grade encryption, ensures your web activity remains private and helps bypass geographic content restrictions online.  Join NordVPN Today and Save up to 73% and Get 3 months Extra Free – Rude Not to …!

CYBERInsights | Practical Small Business Cybersecurity
Image Credit: IfOnlyCommunications
nordvpn

UK Small Business Owner? Join SMECyber Free Now! & Access the SME Cyber Forum – Read, Learn, Engage, Share …

The Latest SME Cybersecurity News, Threat Intelligence & Analysis, Timely Scam Alerts, Best-practice Compliance, Mitigation & Resources specifically curated for UK Based SMEs in a Single Weekly Email direct to your Inbox or Smart Device together with Unrestricted Free Access to our entire SME Cyber Knowledge & Tutorial Library.