An international survey by security vendor Bitwarden shows that an array of bad password practices by the Gen Z age group are posing significant threats to users’ data.

Perhaps the most telling finding is that 59% of Gen Z respondents recycle existing passwords when updating accounts that disclose data breaches, though 79% of survey respondents say they understand that the password practice is risky.

This is the fifth annual World Password Day survey by the firm. More than 2,300 working adults from the United States, the United Kingdom, Australia, France, Germany, and Japan took part in the survey.

Key results of the survey:

  • 72% of both Gen Z and Millennial respondents estimate they have fewer than 25 unique passwords.
  • 38% of Gen Z and 31% of Millennials report changing only a single character or reusing an existing password when prompted to update a credential.
  • 30% of Gen Z respondents often or always forget passwords to important accounts.
  • 55% of all survey respondents have abandoned logging into an account entirely or created a new password just to avoid the hassle of resetting it.

The researchers found that passwords can be a weapon: 44% of Gen Zers changed a streaming service password to remove account access for a family member or friend following an emotional response to something they said or did.

There is some hope. More than eight in ten Gen Zers and Millennials self-report as being at least somewhat likely to use multi-factor authentication (MFA). 

It’s not a panacea, however. “This suggests that younger generations may be compensating for weak password habits, such as password reuse, by relying on MFA as a security safety net. While MFA is a valuable layer of protection, it should not be seen as a substitute for strong, unique passwords,” the press release about the survey says.