This blog post accompanies our video discussion where Intercede’s experts explore how artificial intelligence is fundamentally changing the password attack landscape. Watch the full video for an in-depth conversation on the real-world implications and how to protect your organisation.
The Password Problem Just Got Worse
Passwords have always been the weakest link in cybersecurity. But with artificial intelligence now in the hands of threat actors, that weakness is being exploited faster and more effectively than ever before. As we discuss in detail in our accompanying video, AI is not creating entirely new attack methods, but it is making existing ones orders of magnitude more effective.
AI Makes Password Cracking Dramatically Faster
Traditional brute-force attacks try every possible combination until they find the right password. It is a slow and resource-intensive process. AI changes the game entirely. By training on millions of real passwords leaked from data breaches, machine learning models can identify the patterns humans actually use when creating passwords, things like capitalising the first letter, adding a year at the end, or substituting numbers for letters.
Generative models like PassGAN have been shown to crack around 51% of common passwords in under a minute and approximately 81% within a month. Meanwhile, advances in GPU hardware mean that a rig of 12 NVIDIA RTX 5090 GPUs can brute-force an 8-character lowercase password in roughly three weeks, a 20% improvement on 2024 speeds.
Credential Stuffing at Scale
AI is not just making password guessing faster. It is making credential stuffing, where attackers use stolen username-password pairs across multiple services, far more efficient. In 2024–25, credential stuffing accounted for 22% of all data breaches, making it the single most common breach vector, ahead of phishing. As our experts explain in the video, AI helps attackers prioritise which credentials to try, on which services, and at what times to avoid detection.
Smarter Phishing and Social Engineering
AI-generated phishing emails are now virtually indistinguishable from legitimate communications. Large language models can craft personalised messages that reference a target’s role, recent activity, or company news. When combined with stolen credentials from breach databases, these attacks become devastatingly effective. The attacker does not need to guess your password if they can convince you to hand it over.
What Can Organisations Do?
The answer is not simply “make passwords longer.” While password complexity helps, it is fighting yesterday’s battle. Organisations should be looking at a layered approach that includes checking employee passwords against known breach databases (like Intercede’s Password Breach Database, which contains over 10 billion compromised credentials), deploying phishing-resistant multi-factor authentication such as FIDO passkeys, and moving towards passwordless authentication where possible.
Intercede’s MyID product suite offers exactly this progression, from password security management with MyID PSM, through MFA with MyID MFA supporting FIDO passkeys and biometrics, all the way to PKI-based certificate authentication with MyID CMS. The key is giving organisations the flexibility to strengthen their authentication posture at their own pace.
The Bottom Line
AI has made existing password attacks orders of magnitude more effective, and the era of passwords as a primary defence is ending. Organisations that fail to adapt will find themselves increasingly vulnerable to attacks that are automated, intelligent, and relentless.
▶ WATCH THE FULL DISCUSSION
For the full discussion on how AI is transforming the threat to password-based security, including practical advice on moving beyond passwords, watch our video: “How Does AI Help Bad Actors Use Passwords to Hack Systems.”