
Italy’s credential theft rate triple European average as World Password Day exposes frailties
Italian firms suffer credential theft at three times the European rate, while generative AI creates new vulnerabilities for global corporate security.
On the thirteenth World Password Day, data from the Italian cybersecurity firm Genetee delivers a stark regional indictment: credential theft now affects 67 percent of Italian companies, a rate three times higher than the European average of 25 percent. Viewed from Rome, the figure underscores a paradox—only 17 percent of Italian organisations reported an increase in overall security incidents this year, compared with 33 percent elsewhere in Europe. Yet the qualitative nature of the attacks reveals a concentrated vulnerability.
Italian firms are far more likely to face compromised credentials and Distributed Denial of Service attacks that knock websites offline, suggesting that basic identity hygiene remains dangerously neglected in the country’s corporate sector. Across the continent, the picture is uneven. European businesses have largely improved their baseline defences, but the Italian outlier highlights how national variations in digital literacy and investment can create soft spots for cybercriminals to exploit.
The problem is not confined to the Old World. In the United States, the most common password of 2025 remains an embarrassment of predictability—a reminder that consumer behaviour lags behind threat evolution, even as breaches proliferate. Analysts in London note that the real game-changer is generative artificial intelligence.
A study cited during this year’s awareness day finds that 45 percent of employees globally have fed sensitive corporate data into generative AI tools, unwittingly exposing trade secrets, client lists, and internal strategy to third-party models. This new vector of risk bypasses traditional password protection entirely, striking at the moment of human trust in convenience. The security industry now warns that the password itself, while still a necessary gatekeeper, is no longer sufficient.
From Milan to Madrid, security experts are urging a shift toward multi-factor authentication and behavioural biometrics as the first line of defence. Yet the persistence of weak habits—reusing simple phrases, skipping two-factor verification—means that even the best technology cannot compensate for human complacency. Looking ahead, the convergence of AI-enabled social engineering and credential harvesting will test corporate resilience in ways that simple annual awareness days cannot address.
The next front in digital security may well be not the strength of the password, but the discipline of the person typing it.
Broaden your view
Trump Suspends Planned Iran Strikes, Citing Outline of Deal on Hormuz and Nuclear Programme
2 languages · 74 outlets
From Economy & MarketsIndonesia’s Q2 growth forecasts diverge sharply ahead of official release
2 languages · 11 outlets
From TechnologyFalcon 9 upper stage to strike Moon on 5 August, offering rare scientific opportunity
3 languages · 8 outlets