Kaspersky Study Finds Majority of MD5 Password Hashes Vulnerable to Fast Cracking
In a recent analysis released for World Password Day, Kaspersky researchers found that 60% of MD5-hashed passwords could be cracked in under an hour using a high-end Nvidia RTX 5090 GPU, while 48% could be broken in under a minute. The study examined over 200 million real-world passwords and highlighted that the predictability of passwords significantly aids attackers in optimizing their cracking algorithms. Compared to a similar study in 2024, passwords are slightly easier to crack in 2026, thanks to the growing power of graphics processors. Experts emphasize that the main responsibility lies with service providers to modernize authentication systems and implement stronger security measures, as users often have limited control over password strength requirements. The discussion among cybersecurity professionals also underscores the importance of using salted hashes, modern password hashing algorithms like Argon2id, passkeys, and multi-factor authentication (MFA) to mitigate risks. While MD5 remains widely recognized as insecure, the study serves as a reminder that weak passwords combined with fast hashing algorithms are highly vulnerable to modern cracking techniques, urging both companies and users to adopt stronger, more robust authentication methods.
