Website Security & Threat Management
Password reuse is rampant: nearly half of observed user logins are compromised

Password reuse is rampant: nearly half of observed user logins are compromised

3/17/2025 · Radwa Radwan, Sabina Zejnilovic

What this post added

This post details an analysis of Cloudflare's observed traffic between September-November 2024, revealing that 41% of successful logins involve compromised passwords. It highlights that 95% of login attempts using leaked passwords are bot-driven, indicating widespread credential stuffing attacks. The analysis further breaks down these statistics for WordPress, showing 76% of leaked password login attempts are successful, with 48% being bot-driven. The post emphasizes the role of password reuse as a primary vulnerability and provides recommendations for users and website owners to enhance security.

Read the original post ↗