-

Dashlane Reveals Global Password Health and Hygiene Improving, But Reuse Leaves Users at Increased Risk: New Report

News Summary:

  • Dashlane analysis of 19 million users and 22,000 customer organizations finds share of weak, reused and compromised passwords dropped globally in the past year
  • Share of password reuse remains upwards of 44 percent or more across regions, putting accounts at increased risk of account takeover via password spraying attacks
  • Findings highlight the need to expedite the transition to stronger, phishing-resistant authentication such as passkeys

NEW YORK--(BUSINESS WIRE)--A new report from credential management leader Dashlane has found that password health and hygiene improved globally over the past year, reducing the risk of account takeover for consumers and businesses. Password reuse remains prevalent, however, leaving user accounts particularly vulnerable to password-spraying attacks if they’re not protected by strong multi-factor authentication (MFA).

The second annual Global Password Health Score Report details the password hygiene of Dashlane’s more than 19 million users and 22,000 customer organizations worldwide, based on aggregated, anonymized data. Report findings are based on the Password Health Score, calculated using Dashlane’s proprietary algorithm, which factors in the number of weak, reused/similar, and compromised passwords in each Dashlane user’s vault. Scores range from 20 to 100, with higher scores indicating greater health.

Password health and hygiene improves across-the-board

According to this year’s report, the average Password Health Score was between 70.9 (Northern America) and 78.2 (Eastern Europe). While each region fell within the “Needs Improvement” range (a score between 60-90), all regions did improve their scores by an average of nearly two points in the past year. This is due to a decrease in the number of weak, reused and compromised passwords in every region.

“It’s encouraging to see that people are de-risking their digital lives by improving their password health across-the-board,” said John Bennett, Chief Executive Officer at Dashlane. “The incremental improvements we’re seeing can have an outsized impact on reducing risk for users and their employers, especially from opportunistic, wide-net attacks.”

Reuse remains rampant

Recent password-spraying style attacks that leverage compromised credentials, such as those against 23andMe accounts, illustrate the increased risk and greater exposure that comes from password reuse.

Dashlane found that each of the 14 regions included in the report has a share of 44 percent or more reused passwords, which puts all their accounts at higher risk. Regardless of whether or not a user’s passwords are strong, a reused password can have a domino effect: If one account is compromised, they could all fall down, especially without MFA.

With Dashlane, users can see whether their password has been compromised or reused and quickly generate a new, unique password in its place. The report found that the average user has an overwhelming 227 accounts that require a password, making it unrealistic to expect anyone not using a password manager to be able to adequately secure and manage their digital lives.

“As more of our lives are online, password sprawl increasingly becomes a major issue that Dashlane can help alleviate,” said Donald Hasson, Chief Producer Officer at Dashlane. “As we work to replace the password with a more secure and user-friendly option like passkeys, we need to continue to focus on getting the basics right, like ensuring good password hygiene coupled with strong multi-factor authentication.”

Passkeys can’t come soon enough

The fastest way to boost password health and hygiene is to transition to passkeys — a secure, easy-to-use, and phishing-resistant replacement for passwords. Passkeys don't need to be remembered by users, since they are automatically available directly from the user’s device or password manager.

“The passkey is the most consequential security advancement in decades because it makes the easiest path the most secure for everyday users on a global scale,” said Bennett. “In security, it is rare to have an innovation that is more secure and easier to use. Passkeys give you both, not to mention the benefits they’re going to have for businesses in terms of reducing risk and damage caused by breaches.”

To aid users in their transition to passkeys, Dashlane launched Passkeys Directory, a community-driven resource that tracks and lists all sites that offer passkeys.

To download the Password Health Score report and find out what steps users can take to improve their score, please visit dashlane.com/resources/global-password-health-2023.

About Dashlane

Dashlane offers businesses and consumers a credential management solution that is as easy to use as it is secure. Admins can easily onboard, offboard, and manage their employees with the assurance that company data is safe. And employees can enjoy a way to manage their work and personal accounts that’s already loved by millions. Dashlane’s team in Paris, New York, and Lisbon is united by our passion for improving the digital experience and the belief that with the right tools, we can help everyone realize the promise of the internet. Dashlane has empowered over 19 million users and over 22,000 organizations in 180 countries to dash across the internet without compromising on security.

Contacts

Cable Daniel-Dreyfus
press@dashlane.com

Dashlane


Release Versions

Contacts

Cable Daniel-Dreyfus
press@dashlane.com

More News From Dashlane

Dashlane Launches Global Partner Program to Transform Credential Security for Enterprises

NEW YORK--(BUSINESS WIRE)--Credential security leader Dashlane today announced the launch of the Dashlane Partner Program, a comprehensive and tiered program designed to empower reseller partners in addressing the critical challenge of credential-based threats and providing frictionless access across their customers’ environments. Amid continued credential-driven breaches and attacks targeting identity, the Dashlane Partner Program equips reseller customers with Dashlane’s suite of proactive cr...

Dashlane Goes Beyond Password Management with Proactive Enterprise-Wide Credential Risk Detection

NEW YORK--(BUSINESS WIRE)--Credential security leader Dashlane today launched Credential Risk Detection, the industry’s first solution that continuously monitors and detects at-risk credential activity in real-time across the workforce, whether employees use a password manager or not. The web extension-based solution is the latest Dashlane innovation that shifts credential security from passive defense to proactive protection, enabling enterprises to prevent credential-based breaches, rather th...

New Dashlane Report Finds Pervasive Password Reuse in Enterprise Environments

NEW YORK--(BUSINESS WIRE)--To kick-off Cybersecurity Awareness Month, credential security leader Dashlane today published the third annual Global Password Health Score Report, detailing the global state of password health and hygiene. New to this year’s report is an exclusive analysis of user credential health and practices in business environments, showing significant differences in password health and credential behavior based on organization size. Overall, Dashlane found that password health...
Back to Newsroom