We just cracked 67% of employee passwords during a pen test.
The client was stunned. They had "strict" password requirements: 12 characters, uppercase, lowercase, numbers, symbols, changed every 90 days.
Here's what everyone was actually using:
Summer2024!
Fall2024!