Password Cracking Time
Roughly how long automated guessing of every combination of a password takes, depending on length and character variety. Rough reference points, not an exact science, real attacks often use smarter methods than pure guessing.
Last updated: September 1, 2026
Lowercase letters only
6 charactersSeconds8 charactersMinutes to hours10 charactersSeveral weeks12 charactersSeveral decades14 charactersSeveral centuriesUpper and lower case letters
6 charactersMinutes8 charactersSeveral hours10 charactersSeveral years12 charactersSeveral millennia14 charactersMillions of yearsLetters, numbers and special characters
8 charactersSeveral days10 charactersSeveral centuries12 charactersMillions of years14 charactersBillions of years16 charactersPractically unreachablePassphrase made of words
3 wordsSeveral years4 wordsSeveral centuries5 wordsPractically unreachable6 wordsFar beyond any practical relevanceDigits only, like a PIN
4 digitsInstant to seconds6 digitsSeconds to minutes8 digitsHoursAt the same length, 12 characters
This is how big the difference is purely from the type of characters used, at the same password length.
These values are only rough reference points
The actual time strongly depends on the attacker's computing power. This table assumes purely trying every combination. In practice, passwords are often compromised faster, for example through a data breach at a provider or through phishing, not through brute force guessing. Length still remains the most important factor for a strong password.