Council Post: Password Problems Refuse To Die
Ken O'Brien, CTO of Enzoic.

getty
The top-line finding in Verizon's 2026 Data Breach Investigations Report (DBIR) was that vulnerabilities (31%) overtook credentials (13%) as the key access vector. However, credential abuse across the breach chain remained the most common action at 39%. In fact, the report called it an "attacker favorite" on a "long-running" streak. Companies that lose focus on the frequency and impact of credential abuse risk deprioritizing their defenses, and the data shows exactly why.
Solving The Wrong Problem
After a decade of investing in password complexity, the findings show that the strategy worked: Fewer than 1% of Active Directory accounts failed these checks. However, the same data revealed that 4% had exposed credentials. This means people are four times more likely to be using a password already for sale on the dark web than a weak one.
Meeting every policy requirement is meaningless if it's compromised. A decade of investment solved the wrong problem. The rules determine how a password is constructed, but they fail to establish whether it has already been leaked in a third-party incident, harvested by an infostealer or traded on criminal marketplaces.
Compounding the problem is the long-standing issue of reuse. When people employ the same password across multiple systems, a single incident can expose access to corporate networks, email, VPNs and applications. Composition policies and periodic resets do nothing to address this.
The impact is visible across DBIR categories. Stolen credentials remain the most common action in basic web application attacks, where bad actors use them to take over accounts, access sensitive data or move laterally within corporate networks. Without checks against breach databases, cybercriminals can walk through the front door using passwords that tick every policy box.
How Exposed Credentials Fuel Ransomware
The DBIR painted a stark picture. It found that 73% of ransomware victims had a credential or infostealer leak in the past year, with half experiencing it within 95 days of the attack. This reflects a mature ecosystem where login data is harvested through phishing and infostealers and then aggregated and sold on the dark web before being weaponized for access and escalation. Stolen credentials are often packaged with the valid URL, reducing exploitation to a login.
The 95-day window suggests many enterprises lack the visibility to detect a compromise before an attacker utilizes it. Additionally, size offers no protection. Small businesses, on average, experienced seven leak events per year, compared with 20 for larger entities.
AI is amplifying the threat. Data contributed by Anthropic to the study showed that 21% of AI-assisted attacks involved credential abuse. Critically, the technology is scaling existing attack techniques, enabling bad actors to harvest and use stolen logins faster and more efficiently than ever.
The Industry Ignoring The NIST Playbook
NIST has been recommending compromised credential screening since 2017, with the latest iteration now SP 800-63B-4 (Revision 4). The guidance is clear: Stop relying on composition rules and periodic rotation. Instead, enterprises should check passwords against known breach databases when they're created and on an ongoing basis. A complex password that's already exposed offers zero security compared to a simple, unique one.
A one-time check isn't sufficient, given the volume of breaches. To be an effective deterrent, screening requires continuous monitoring. A password could be secure today and then appear in a leak tomorrow, and without ongoing detection, security teams have no way of knowing that the situation has changed. The data validates that the industry adopted the complexity guidance but ignored the screening requirement.
Same Gap, Same Outcome
Despite numerous predictions that passwords are going to become extinct, they'll coexist with passkeys and biometrics for the foreseeable future. Legacy systems, interoperability challenges and fallback authentication requirements mean they remain integral to identity management. Businesses that shift from periodic enforcement to continuous exposure monitoring can strengthen their defenses.
Cybercriminals are harvesting, trading and exploiting access data at scale, and the narrow window between a leak and a ransomware attack leaves little margin for response. Unless the industry heeds the NIST recommendations and commits to continuously checking for stolen credentials, the 2027 DBIR will tell the same story.
Password problems refuse to die. It's time for defenses to catch up.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?