chiprook
← Security
SecuritySeptember 22, 2026, 21:30

Study: 154 users logged into 26 sites with fewer than 10 passwords, ~60% reused

Carnegie Mellon researchers tracked the logins of 154 people for an average of 147 days via a browser extension that hashed passwords on-device. Participants logged into 26 web domains each using fewer than 10 distinct passwords, with roughly 60% reused outright or built from fragments of other passwords. On financial sites, 85% of passwords also appeared elsewhere.

#CarnegieMellon
Read next
Security

Zimperium finds RatHat: AI-powered Android malware steals passwords and 2FA codes

Security

Synthetic IDs drive half of UK insurance fraud, report finds

Security

Hacktron used zero-day to reach OpenAI's GitHub, sparking disclosure debate

Security

Microsoft disrupts EvilTokens phishing service that hit 12,000 accounts