Skip to main content
Advertisement
Live broadcast
Main slide
Beginning of the article
Озвучить текст
Select important
On
Off

A third of Russian users use only three passwords to access their accounts, according to experts from the DLBI data leak intelligence and darknet monitoring service. As experts have noted, attackers can pick up such a combination in a second and even faster. For more information about why Russian passwords are vulnerable to fraudsters, how dangerous it is, and how to protect yourself from such threats, see the Izvestia article.

What passwords do Russian users use?

Less than half of Russians use four or more passwords to log into their accounts, experts from the Russian DLBI data leak intelligence service found out in a study. Login-password pairs published on Darknet platforms and in closed Telegram channels became the basis for the analysis, the company's experts told Izvestia.

телефон
Photo: IZVESTIA/Dmitry Korotaev

How many passwords do Russian users use?:

— 4-7 passwords — 47% of users;

— 1-3 passwords — 30% of users;

— 8 or more passwords — only 23%.

DLBI experts noted that hackers will need about three minutes to crack an account in popular email services or social networks, going through 10 passwords, most of which will take forced pauses after three unsuccessful attempts. If the user uses three or fewer unique combinations, it can be selected in less than a second.

хакер за работой
Photo: Global Look Press/Annette Riedl

"The situation is only getting worse over time, and people are less likely to try to come up with new passwords," the researchers emphasized. — For example, a few years ago, 22% of Russians used one or three passwords, while only 37% used four or seven passwords. And this is despite the fact that today you can create a unique combination to access a resource not only using a password manager, but also through almost any browser.

How do Russian users' passwords get online?

One of the most common channels of credential leakage is hacking into databases of websites, online stores, large companies and services, says Vitaly Fomin, head of the information security analyst group at the Digital Economy League, in an interview with Izvestia.

— Even if such information is encrypted, modern methods allow you to disclose a significant part of this information and gain access to personal data. In addition, fraudsters often resort to phishing attacks," says the expert.

According to Vitaly Fomin, another channel for obtaining data is fake websites or services like "Public Services", which not everyone can distinguish from the real ones. In addition, hackers often install malicious software on users' devices to steal confidential information, including passwords. Such programs can record keystrokes on the keyboard, and then transfer the data for hacking.

пароль
Photo: Global Look Press/IMAGO

TOP 10 most popular passwords leaked in 2024 (DLBI data):

123456 (retained the first place);

12345678 (ranked fourth in 2023);

123456789 (ranked second in 2023);

Password (new password);

1234 (new password);

12345 (ranked fifth in 2023);

1234567890 (retained seventh place);

1234567 (new password);

password (new password);

- 102030 (new password).

It is important to understand that it is not the passwords themselves that are stolen in their "pure" form, but their hash casts, which make it possible to quickly select the initial combination using the well-known hash generation algorithm, says Maxim Alexandrov, an expert in Security Code software products.

Безопасность
Photo: Global Look Press/FrankHoermann/SVEN SIMON

Attackers can use these combinations to gain access to various popular services, since users often use the same password for different platforms. In addition, hacked accounts often become part of a botnet, the expert notes.

What are the dangers of password leaks for users and their employers?

Anyone, even a cautious user, can suffer from a data leak, Alexander Vurasko, Director of Development at the Solar AURA External Digital Threat Monitoring Center (Solar Group), says in an interview with Izvestia. For example, if someone else's mistake is to blame.

— You placed an order in an online store, and a few months later it was hacked, and your data, along with the password, ended up in the hands of intruders. Although passwords should not be stored in clear text, many companies do not follow security rules carefully," says the specialist. If the company has weak security, hackers will only need a special program and a powerful computer to break in.

Such leaks are dangerous not only for the loss or disclosure of confidential data, but also for the possible expansion of fraudulent schemes: the information obtained can be used to attack the user's immediate environment. Social engineering is used here, Maxim Alexandrov adds.

Interestingly, those who use fewer than seven unique passwords are guaranteed to use one of them on the corporate network, says Ashot Oganesyan, founder of the DLBI service. And in this case, not only the person is in danger, but also his employer.

Взлом
Photo: IZVESTIA/Dmitry Korotaev

If a company provides access to its resources from the outside, for example, for remote work, a small number of passwords of such a user can be easily checked by brute force.

"It is somewhat difficult to select a corporate e-mail based on the leaked one, but hackers have long learned how to solve this problem automatically using the results of scraping social networks," Ashot Oganesyan emphasizes.

How can users protect themselves from password hacking by scammers

Russians refuse to use many different passwords for a number of reasons, but mainly because a complex alphanumeric password is more difficult to remember, explains Maxim Alexandrov. Especially if the combination additionally includes letters of different case and special characters. And considering that a strong password doesn't have to be meaningful, it becomes even more difficult to remember it.

— But even if the user has come up with and memorized a complex password, the level of cyber hygiene among many users is not very high. Therefore, the same combination is used to log in to "Public Services" and for less secure sites," says the specialist. — A leak from the database of one portal will lead to the loss of accounts on more serious resources.

Until the user is hacked, it is quite difficult for him to imagine the consequences of a frivolous approach to password compilation, which is multiplied by laziness and habit, adds Sergey Polunin, head of the IT infrastructure solutions protection group at Gazinformservice. However, the services themselves often indulge in such psychology, without setting requirements for passwords and their complexity.

Кибербезопасность
Photo: IZVESTIA/Sergey Lantyukhov

The best way to protect yourself from hacking is to use complex passwords without meaning (for example, a set of random letters, numbers, and symbols) that are impossible to guess, says Alexander Vurasko. Special password generators that create reliable combinations for users are great for this.

A password manager, a program that, on the one hand, securely stores data, and on the other hand, automatically substitutes it when logging on to websites, will help you not forget this combination. Moreover, many managers already have a built—in password generator, which is convenient and secure.

"Both users and companies can be advised to generate unique passwords, make the most of two—factor authentication, and do not neglect data leak detection services," concludes Ashot Oganesyan. According to the expert, companies can connect their account storages to such services directly and block compromised logins and passwords as quickly as possible.

Переведено сервисом «Яндекс Переводчик»

Live broadcast