GeneratePass
Security Guide • 11 min read

How Password Breaches Happen

By GeneratePass Developers | Published: June 15, 2026 | Last Updated: June 15, 2026

Passwords remain the primary authentication mechanism across billions of accounts, yet most users choose passwords that are trivially guessable. According to NordPass, the average person manages over 160 passwords, leading to reuse and predictable patterns. When an attacker obtains a password—whether through a breach, phishing, or brute force—they often gain access to far more than one account.

This article dives deep into the technical mechanics of how passwords are specifically targeted, stolen, and cracked. Understanding these attack vectors is essential for choosing passwords that resist real-world attacks.


How Passwords Are Stored (and How They’re Stolen)

When you create an account, the service stores your password—or a representation of it—in a database. How that password is stored determines how badly a breach compromises you. Not all storage methods are equal.

Storage MethodSecurity LevelWhat Happens in a Breach
PlaintextNonePasswords are immediately readable. Game over.
MD5 (unsalted)Very WeakReversed in milliseconds via rainbow tables or GPU brute force.
SHA-1 (unsalted)WeakCracked in seconds. Rainbow tables cover all 8-character passwords.
SHA-256 (unsalted)WeakSlightly harder than SHA-1, but still defeated quickly with GPUs.
bcrypt / scryptStrongComputationally expensive. Hours to days per password on modern GPUs.
Argon2Very StrongMemory-hard algorithm. Resists GPU and ASIC attacks. Best available today.

A critical detail: salting—adding a unique random value to each password before hashing—defeats rainbow tables entirely. A salted MD5 hash cannot be reversed with a precomputed lookup table because each password has a different hash value. However, salting alone does not protect against offline brute-force attacks if the hash algorithm is fast (like MD5 or SHA-1).

Services that store passwords in plaintext or use weak, unsalted hashes expose every user the moment their database is compromised.


SQL Injection: Extracting Passwords from Databases

SQL injection (SQLi) remains one of the most devastating attack vectors for password theft. When a web application fails to sanitize user input, an attacker can manipulate the underlying database query to extract data that was never meant to be returned.

How it works in practice

Consider a login form that builds a query like:

SELECT * FROM users WHERE username = 'INPUT' AND password = 'INPUT'

An attacker enters ' OR '1'='1' -- as the username. The query becomes:

SELECT * FROM users WHERE username = '' OR '1'='1' --' AND password = ''

The -- comments out the password check, and '1'='1' is always true. The database returns all rows in the users table, typically logging the attacker in as the first user—often the administrator.

Extracting entire password databases

More sophisticated SQLi attacks use UNION-based or blind injection to extract data column by column. An attacker can dump the entire users table including password hashes:

' UNION SELECT username, password_hash FROM users --

This is how breaches like the 2012 LinkedIn incident (117 million unsalted SHA-1 hashes) and the 2013 Adobe breach (153 million weakly encrypted passwords) occurred. Once the hashes are extracted offline, the real cracking begins.


From Hash to Plaintext: How Attackers Reverse Passwords

When attackers obtain a database of password hashes, the real work begins. The goal is to convert each hash back into the original plaintext password. The method depends on how the password was hashed.

Rainbow Table Attacks

Rainbow tables are precomputed lookup tables that map hash values to their plaintext equivalents. For a given hash algorithm, a rainbow table covers a specific character space (e.g., all passwords up to 8 characters using lowercase letters and digits).

For unsalted MD5, a complete rainbow table for 8-character alphanumeric passwords fits in roughly 300 GB. An attacker looks up a hash and gets the password in milliseconds. Rainbow tables are useless against salted hashes because each password produces a different hash value.

Offline GPU Brute Force

When rainbow tables don’t apply (e.g., salted hashes or longer passwords), attackers use GPU clusters to test billions of candidate passwords per second:

Hash AlgorithmSpeed (10x RTX 4090 GPUs)8-char Password
MD5~300 billion hashes/sec< 1 second
SHA-1~100 billion hashes/sec< 1 second
SHA-256~40 billion hashes/sec< 1 second
bcrypt~1 million hashes/sec~3 years
Argon2~100 thousand hashes/sec~30 years

Tools like Hashcat and John the Ripper automate this process. A modern rig can exhaust the entire keyspace of short, simple passwords in minutes.

Dictionary and Rule-Based Attacks

Pure brute force is inefficient for long passwords. Instead, attackers use dictionary attacks—testing words, phrases, and common password patterns first. Hashcat applies transformation rules (capitalizing the first letter, appending numbers, substituting a with @) to expand dictionary coverage.

A dictionary attack with rules can crack 60-80% of human-chosen passwords within hours, because people gravitate toward predictable patterns: Password123!, Summer2026, Company123.

Password Spraying

Rather than trying many passwords against one account, password spraying flips the approach: try one or two common passwords against thousands of accounts. This avoids account lockouts while exploiting the fact that many users share the same weak passwords. Common spray passwords include Welcome1, Summer2026, Company123!, and seasonal variations.

Password spraying has been the initial vector in breaches at major organizations, including the 2019 Capital One breach and multiple Microsoft 365 compromises.


Credential Stuffing: Weaponizing Leaked Passwords

Credential stuffing is the automated injection of stolen username/password pairs into login forms across multiple websites. It exploits the fact that over 60% of users reuse passwords across different services.

The attack lifecycle

  1. Harvest: Attackers obtain leaked credential databases from previous breaches.
  2. Parse: Credentials are deduplicated and formatted into username:password pairs.
  3. Spread: Automated tools (Sentry MBA, OpenBullet, custom scripts) test these pairs against high-value targets—banks, email providers, cloud storage, corporate VPNs.
  4. Monetize: Successful logins are sold, used for identity theft, or leveraged for lateral movement within corporate networks.

Why it works

Credential stuffing succeeds because the barrier to entry is low and the success rate is surprisingly high. Research by Akamai found that credential stuffing attacks account for over 3 billion malicious login attempts annually. Even a 0.1% success rate across billions of attempts yields millions of compromised accounts.

Defenses

  • Unique passwords per account (eliminates the reuse vector)
  • Rate limiting and CAPTCHAs on login endpoints
  • Anomaly detection (flagging login attempts from unusual IPs or geolocations)
  • Credential breach monitoring (checking new passwords against known leaks)

You can verify if your credentials have been exposed in past leaks using our secure Password Breach Checker.


Pass-the-Hash Attacks

In enterprise environments, pass-the-hash (PtH) allows an attacker to authenticate to a remote server using a stolen password hash without ever cracking it to plaintext. This is possible because some authentication protocols (like NTLM) transmit a hash of the password rather than the password itself.

Once an attacker obtains a password hash—often through dumping the LSASS process on a Windows machine or extracting hashes from Active Directory—they can inject that hash directly into an authentication session. The server sees a valid hash and grants access. No brute force required.

PtH is a major concern in corporate networks because a single compromised workstation can give an attacker access to servers, databases, and domain controllers. Microsoft has worked to mitigate PtH with Protected Users security groups and Credential Guard, but it remains a viable attack vector in environments running legacy authentication protocols.


The Password Crack Economy

Stolen password hashes are traded and cracked at industrial scale:

  • Cracking-as-a-service: Dark web forums offer GPU cracking services for $10-$50 per hash list, depending on algorithm and volume.
  • Hash markets: Pre-cracked password databases sell for $100-$5,000, with banking and corporate credentials commanding premium prices.
  • Combo lists: Aggregated username:password pairs from multiple breaches are bundled and traded freely on forums, often containing billions of entries.
  • Fresh credentials: Accounts from recent breaches sell for $1-$10 per set on dark web marketplaces.

The scale is staggering. In 2024 alone, an estimated 30 billion credentials were available on dark web marketplaces. The efficiency of modern cracking infrastructure means that weak passwords are effectively public knowledge within hours of a breach.


Building Passwords That Resist These Attacks

Understanding the attack vectors tells us what a password must withstand:

  • Rainbow tables and dictionary attacks → Use random characters, not dictionary words.
  • GPU brute force → Use long passwords (16+ characters) to make the keyspace infeasible.
  • Credential stuffing → Never reuse a password across services.
  • Password spraying → Avoid common patterns (seasonal, keyboard walks, company name + number).

Practical steps:

  • Generate passwords using our Password Generator — cryptographically random, never sent over the network.
  • Measure resistance with our Password Entropy Calculator — know exactly how many bits of entropy your password has.
  • Verify strength with our Password Strength Checker — catch weak patterns before you commit to a password.
  • Use a password manager to store unique passwords for every account.
  • Enable hardware security keys (FIDO2/WebAuthn) where available — they are immune to phishing, credential stuffing, and pass-the-hash attacks.

Frequently Asked Questions

How do I know if my password has been leaked in a breach? You can use a secure breach checker like our [Password Breach Checker](/breach-checker/) to verify if your credentials appear in known public data breach databases. The tool uses k-anonymity hashing to check your password without ever exposing it over the network.
Can a leaked hash be reversed to get my password? It depends on the hashing algorithm used. If the service used MD5 or unsalted SHA-1, yes—your password can be reversed almost instantly. If they used bcrypt, Argon2, or PBKDF2 with proper salting, your password is computationally infeasible to reverse within any practical timeframe. Check the entropy of your passwords with our [Password Entropy Calculator](/entropy-calculator/).
Is MFA enough to protect me if my password is leaked? MFA significantly reduces risk but is not invincible. Some advanced attacks—such as real-time phishing proxies (e.g., Evilginx) and session hijacking—can bypass certain MFA methods. Hardware security keys (FIDO2/WebAuthn) provide the strongest MFA protection. Always use MFA alongside strong, unique passwords.
How long does it take to crack a strong password? With modern GPU rigs, a 12-character random password using all character classes would take billions of years to brute force. The critical factors are length and randomness—passwords like `Tr0ub4dor&3` are far weaker than `kX#9mP$2vLq8nR@w` despite similar apparent complexity. Use our [Password Entropy Calculator](/entropy-calculator/) to see the difference.
What is pass-the-hash and should I be worried? Pass-the-hash is an attack where an attacker uses a stolen password hash to authenticate without knowing the plaintext password. It primarily affects enterprise environments using NTLM authentication. For individual users, the risk is indirect—protecting your devices from malware and using unique passwords limits exposure. Hardware security keys and modern authentication protocols (Kerberos with AES) are not vulnerable to pass-the-hash.

GeneratePass Developers

Developers of GeneratePass, building client-side security tools and educational content focused on local execution, zero-trust patterns, and client-side data sovereignty.

Focus: Cryptography • Standard: zero-trust