Convenience leads many people to choose weak passwords, and AI is making it increasingly easy for bad actors to crack those passwords and gain access to personal and banking information.
“The systemic vulnerability of human-selected passwords has been an open secret for decades,” Frances Zelazny, general manager of new market initiatives at consumer verification/authentication software provider Prove, told FinAi News.
“Security professionals have long known that the most popular password globally remains some variation of the word ‘password’ itself.”

About 80% of data breaches in 2025 resulted from weak or stolen passwords, according to Verizon‘s 2026 Data Breach Investigations Report, released in May. To combat this, many banks offer multistep authorization, which can include a user inputting a QR code or biometrics alongside a password.
With AI, scammers no longer need to rely on slow, manual, brute-force guessing to determine someone’s password, Zelazny said. AI can find and analyze massive amounts of data from across the internet, which can be used to uncover passwords with higher accuracy.
“AI does not just guess passwords; it autonomously orchestrates the deception required to extract them,” Zelazny said. “The weak foundation that our identity systems are built on is crumbling.
“AI is not creating these basic human oversights,” she said. “Rather, it is weaponizing them at industrial scale while introducing entirely new layers of account-takeover risks.”
Password complexity
Survey results released June 30 by business and technology consultancy Capco show that 40% of respondents find complex passwords frustrating or inconvenient.
Nevertheless, while even strong passwords can be cracked, they are less likely to be, and the time it takes to crack them can deter bad actors, Zelazny said.
When creating a password, the U.S. Cybersecurity and Infrastructure Security Agency advises users to:
- Make it at least 16 characters;
- Use either a random string of mixed-case letters, numbers and symbols or a string of four to seven unrelated words; and
- Make it unique, meaning it is not your password anywhere else.
When the cost is too high
But passwords that are unique and complex are harder to remember.
In a survey of 7,861 residents from eight countries, online security and privacy company Nord Security found that 40% of respondents store online passwords in their browsers.
When asked why they use this unsecure password-storage method, respondents were able to choose multiple options and:
- 51% of respondents said convenience;
- 44% said ease-of-use; and
- 32% said because it is free.
Twenty-nine percent said it was because they trust the browser provider and 28% said they believed the service was “secure enough,” according to the survey results released in June.
“It seems that a lot of people are making password storage decisions on a whim,” Karolis Arbaciauskas, head of products at Nord Security, said in a statement sent to FinAi News. “But this approach poses serious risks.
“When you are using free products, you usually pay with your data.”
Many cybersecurity experts recommend using a dedicated password manager, which may cost money at the outset but could save the user money in the long run by avoiding fraud.
FinAi Lending Summit, set for Oct. 7-8 in Las Vegas, will include speakers from Fifth Third and Capital One as well as a fireside chat with U.S. Bank Senior Vice President – Lending Operations Group Manager Suzanne Rathbun. To learn more about the 2026 event and register, visit here.





