
3/17/2025 · Radwa Radwan, Sabina Zejnilovic
What this post added
This post details an analysis of Cloudflare's observed traffic between September-November 2024, revealing that 41% of successful logins involve compromised passwords. It highlights that 95% of login attempts using leaked passwords are bot-driven, indicating widespread credential stuffing attacks. The analysis further breaks down these statistics for WordPress, showing 76% of leaked password login attempts are successful, with 48% being bot-driven. The post emphasizes the role of password reuse as a primary vulnerability and provides recommendations for users and website owners to enhance security.