The passwords of 32 million users from a breach were analyzed. It was found that 30% of passwords were 6 characters or less, 60% used a limited set of characters, and the most common password was "123456". Only 0.2% of passwords met basic strength recommendations like length and mix of characters. The short and simple passwords chosen by many users leaves them vulnerable to brute force attacks.