More than half of the passwords compromised in 2025 had already appeared in earlier data breaches, highlighting widespread password reuse and long-term security risks, according to new research by global cybersecurity firm Kaspersky.
The findings are based on Kaspersky’s analysis of major password leaks between 2023 and 2025, which showed that 54 per cent of passwords exposed in 2025 were reused from previous breaches, according to a press release.
The research found that many users continue to rely on weak and predictable passwords, often including dates, names, or common number patterns such as “12345,” significantly reducing account security.
Around 10 per cent of leaked passwords contained date-like numbers, while most compromised passwords remained unchanged for an average of 3.5 to four years, making them vulnerable to brute-force and credential-stuffing attacks.
Kaspersky said these trends highlight the growing risks of traditional password-based authentication as cybercriminals increasingly exploit reused credentials across multiple platforms.
To address the issue, the company has introduced passkey technology to Kaspersky Password Manager, allowing users to log in using cryptographic keys and biometric authentication instead of passwords.
The company said passkeys are resistant to phishing and data leaks and can be securely stored and synchronised across devices.
Kaspersky Vice President for Consumer Business Marina Titova said managing multiple passwords often undermines both security and convenience, adding that the new passkey feature offers a simpler and more secure way to protect accounts.
Kaspersky advised users to update Kaspersky Password Manager and follow in-app guidance to create and securely store passkeys on supported websites.





