Drooid Logo
Back to story perspectives

Full Breakdown

World Password Day Highlights Cracking Speed of MD5 Hashes and Accelerates Push Toward Passkeys

5/8/2026, 9:09:54 PM

Rapid Cracking of MD5 Password Hashes

Security firm Kaspersky analyzed a dataset of more than 231 million unique passwords obtained from dark-web leaks, adding 38 million since its 2024 study. When those passwords were hashed with the fast algorithm MD5 and attacked using a single Nvidia RTX 5090 graphics card, 60 % were cracked in under one hour and 48 % in less than 60 seconds. The researchers note that attackers can rent comparable GPUs from cloud providers for only a few dollars, making large-scale cracking economically feasible.

Why Passwords Remain Vulnerable

Kaspersky attributes the ease of cracking to two factors: the speed of MD5 and the predictability of user-chosen passwords. Their analysis of over 200 million exposed passwords revealed common patterns that allow cracking tools to prioritize likely character combinations, further reducing attack time. The study also found that passwords have become marginally easier to crack since 2024, a trend Kaspersky links to the continual increase in graphics-processor performance.

Key Statistics on Cracking Speed and Authentication Shifts

  • 231 million passwords tested; 60 % cracked < 1 hour, 48 % < 1 minute.
  • 22 % of confirmed breaches in 2026 still began with stolen credentials (Security Brief).
  • Only 47 % of organisations have deployed multi-factor authentication (MFA) as a standard.
  • 90 % of consumers in ten countries are aware of passkeys; 75 % have used them for at least one account (FIDO Alliance).
  • 68 % of surveyed organisations are deploying or piloting passkeys, but only 30 % have made passkeys their primary authentication method.
  • 57 % of IT leaders recognise passkeys’ importance, yet 38 % cite legacy-system compatibility as a barrier.

Official Statements & Responses

Kaspersky emphasized that “one hour is all an attacker needs to crack three out of every five passwords they’ve found in a leak.” CISO-for-hire Chris Gunner (Thrive) warned that “even a strong password can be undermined if the wider identity and access environment is not properly managed,” and advocated pairing passwords with biometric MFA and a zero-trust architecture. Steven Furnell, professor of cybersecurity at the University of Nottingham, argued that the focus should shift from users to “sites and providers that are requiring them to [use passwords].”

The UK’s National Cyber Security Centre (NCSC) announced an “overhaul of decades of practice” by urging the public to stop relying on passwords, while India’s CERT-In continues to stress stronger password hygiene and MFA. Marcus Lauren, chief product officer at NEXT Biometrics, linked the timing of World Password Day to “rising geopolitical tension and an increasingly hostile cyber threat landscape.”

Criticism & Opposition

Adoption of passkeys faces practical obstacles. Danny de Vreeze (Thales) noted that despite 87 % of IT leaders recognising passkeys, only 49 % have deployed them, citing “compatibility with legacy internal systems,” budget approval, and “concerns over device recovery and account restoration.” Security researcher Trevor Hilligoss (SpyCloud) warned that even with passkeys, attackers can hijack validated browser cookies, allowing access without credential entry.

Verbatim Quotes

  • “One hour is all an attacker needs to crack three out of every five passwords they’ve found in a leak,” — Kaspersky
  • “Even a strong password can be undermined if the wider identity and access environment is not properly managed,” — Chris Gunner, CISO-for-hire, Thrive
  • “This World Password Day, the main message ought not to be to the users, who often have no choice but to use passwords anyway, but to the sites and providers that are requiring them to do so,” — Steven Furnell, University of Nottingham
  • “World Password Day this year comes against a backdrop of rising geopolitical tension and an increasingly hostile cyber threat landscape.” — Marcus Lauren, NEXT Biometrics
  • “And the threat landscape doesn't pause while you do.” — Chris Newton-Smith, CEO, IO

What’s Next

Industry analysts predict that passkeys will become the dominant authentication method within the next few years, prompting organisations to audit MFA coverage, retire MD5-based password storage, and integrate continuous identity verification into zero-trust frameworks. The NCSC’s guidance and the FIDO Alliance’s adoption reports suggest a coordinated shift away from password-only logins toward biometric-linked, device-bound credentials.