Original research · T.O. Mercer · June 2026
How long does it take to crack a password in 2026?
We ran the numbers on current hardware. The honest answer swings from instant to longer than the universe has existed, and it turns on two things almost nobody thinks about: how the website stored your password, and whether you invented it yourself.
Check a password shape
Pick a length and character set. This is the time to try every possible combination of that shape, assuming a truly random password. An attacker finds it in about half that time on average.
Time to brute-force
—
The 2026 crack-time table
Every cell is the time to brute-force a random password of that length and character set. Flip the hashing toggle above and watch the whole table change colour. Same passwords, two ways the site could have stored them.
Time to brute-force a random password
The table only protects a random password
If you made your password up, none of these numbers apply to you.
The grid assumes every character is random. Real passwords almost never are. They are built from words, names, dates, and predictable swaps like P@ssw0rd!. Pattern-based and machine-learning cracking, from PassGAN to its 2026 successors, targets exactly that structure. A human-chosen password usually falls in a tiny fraction of the time its length and character set suggest, no matter how complex it looks. Test your password habits with our pattern checker to see whether your style is closer to random or predictable. The only way to actually earn the green end of this table is to let software generate the password for you.
Generate a random passwordMethodology
Everything here is reproducible. If you want to argue with a number, argue with these assumptions, not a black box.
Cite this
Suggested citation
T.O. Mercer, “How long does it take to crack a password in 2026?” SafePasswordGenerator.net, June 2026.