Only 36% of US adults, about 94 million people, currently use a password manager, an increase of just two percentage points over last year, according to Security.org’s fourth-annual report. Passkeys, the password-less alternative, have reached global scale with 5 billion now in active use.
Most of the passkey scaling is happening on the same Apple and Google infrastructure that already dominates password-manager market share.
Key Takeaways
- 36% of US adults use a password manager today, with about 94 million users in the United States; adoption rose 2 percentage points year over year.
- Tech giants dominate the category: Google and Apple together control over 55% of the US password-manager market through their proprietary services.
- 5 billion passkeys are now in active use globally, and 90% of consumers are familiar with passkeys per the FIDO Alliance.
- Credential abuse fell to 13% of breaches in the 2026 Verizon DBIR, the first time in 19 years that credential theft has not topped the initial-access vector rankings.
- Gen Z is the highest-adoption cohort at 46% but also the most likely to reuse passwords at 72%, per Bitwarden’s annual global survey.
- The UK Information Commissioner’s Office fined LastPass £1.2 million in December 2025 over the 2022 data breach that compromised personal information on up to 1.6 million UK customers.
- Users with password managers were less likely to experience identity theft or credential theft in the past year compared with those without (17% vs. 32%).
Editor’s Choice
- Google Password Manager is the most-used service in the United States with about 32% of users, followed by Apple’s iCloud Keychain or Passwords app at 23%.
- LastPass sits at about 11% US share; Bitwarden is chosen by about 10% of US users.
- 68% of organizations are deploying, piloting, or rolling out passkeys for employee authentication, according to FIDO Alliance workforce data.
- 5.3 billion stolen credential pairs are circulating in criminal underground sources, and 4 in 10 corporate users have reused an exposed password, per the 2026 Verizon DBIR.
- Over 75% of non-users say they are open to adopting a password manager if it offers the right combination of usability, security, and affordability.
- At 46%, Gen Z is most likely to use password-management software, ahead of 39% for Millennials and 33% for Gen X.
- 4% of Active Directory user accounts use passwords that have already been compromised elsewhere, according to Verizon DBIR breach corpus data.
Recent Developments
- May 2026, The FIDO Alliance announced on World Passkey Day 2026 that 5 billion passkeys are now active globally and 49% of people use passkeys regularly when available.
- May 2026, Verizon published its 2026 DBIR showing vulnerability exploitation overtaking credentials as the dominant initial access vector at 31% versus 13% for credential abuse, the first such shift in the report’s 19-year history.
- March 2026, Security.org released its fourth-annual password manager study, with US adoption at 36% and over 55% combined Google plus Apple market share.
- December 2025, The UK Information Commissioner’s Office fined LastPass UK Ltd £1.2 million for the 2022 data breach affecting up to 1.6 million UK customers.
- May 2025, Bitwarden published its annual global survey of over 2,300 employed adults across six countries, with 72% of Gen Z respondents reusing passwords versus 42% of Boomers.
Beyond the headlines, the adoption picture below shows where the next wave of users sits and why most of the growth is happening on consumer rails; most people do not consider a “password manager” at all.
Password Manager Adoption Rates
US password-manager adoption sits at 36% of adults, about 94 million people, per Security.org’s 2026 update, up from 34% a year earlier. The trajectory has been slow but linear since 2020, with each annual study adding two to three percentage points to the user base.
How many people use password managers?
36% of US adults, roughly 94 million people, use a password manager according to the Security.org 2026 report, an increase of 2 percentage points over last year. Pew Research Center data shows password-manager use rose from 20% in 2019 to 32% in 2023, reflecting steady adoption.
Adoption Snapshot
| Metric | Value |
|---|---|
| US adults using a password manager | 36% |
| Estimated US user count | ~94 million |
| Year-over-year change | +2 percentage points |
Source: Security.org 2024 Password Manager Industry Report (updated March 2026)
The adoption ceiling is higher than the current rate suggests. Over 75% of non-users say they would consider a password manager if it offered the right balance of usability, security, and affordability; the gap between current 36% adoption and a 75% addressable ceiling represents roughly 100 million additional potential US users. That trust-and-use gap, not technology, is the headline constraint on the category through the rest of this decade.
Password Manager Market Share by Provider
The US market is concentrated, with Google and Apple together controlling over 55% of the password-manager market through their proprietary services. Dedicated paid managers (LastPass, Bitwarden, 1Password, Dashlane, Keeper) split most of the remainder.
| Provider | US share |
|---|---|
| Google Password Manager | ~32% |
| Apple iCloud Keychain / Passwords | ~23% |
| LastPass | ~11% |
| Bitwarden | ~10% |
| All other (1Password, Dashlane, Keeper, NordPass, Proton Pass, etc.) | ~24% |
Source: Security.org 2024 Password Manager Industry Report (updated March 2026)
Almost 32% of users said they mainly used Google Password Manager in 2024 when surveyed by Security.org, and Apple’s iCloud Keychain or Passwords app came next with 23%. LastPass held about 11% share and Bitwarden about 10% in the same survey.
By the numbers: Per Security.org’s 2026 update, Google and Apple together carry over 55% of the US password-manager market through services that ship with the operating system or browser, a structural advantage that paid challengers like 1Password and Bitwarden have not been able to dent, even as the dedicated-manager category grew through 2024 and 2025.
What is the best password manager?
There is no single “best”; the right choice depends on the use case. Security.org’s 2026 ranking shows Google Password Manager leading with about 32% of US users, followed by Apple iCloud Keychain at 23%, LastPass at 11%, and Bitwarden at 10%. Browser-native managers win on convenience; standalone managers (Bitwarden, 1Password, Dashlane) tend to win on cross-platform sync, sharing, and enterprise features. SQ Magazine does not recommend a specific product.
Demographics: Who Uses a Password Manager
Adoption skews younger and higher-income. Gen Z is most likely to use password-management software at 46%, ahead of 39% for Millennials and 33% for Gen X, according to Bitwarden’s 2025 World Password Day Global Survey.
| Generation | Password-manager adoption |
|---|---|
| Gen Z | 46% |
| Millennials | 39% |
| Gen X | 33% |
| Boomers | (not separately reported) |
Source: Bitwarden World Password Day Global Survey 2025 (n>2,300)
Bitwarden’s annual global survey covered over 2,300 employed adults across the United States, Australia, the United Kingdom, Germany, France, and Japan, a methodology that captures the working-age, internet-active population rather than the general adult base Security.org samples.
Worth noting: Self-reported adoption among Gen Z runs well ahead of measured adoption across older cohorts, but the same generation is also the most likely to share credentials through insecure channels, 25% of Gen Z share passwords via text, 19% share screenshots, and 19% share verbally. Convenience drives both the higher adoption and the riskier behavior.
Password Reuse and the Adoption Gap
Password reuse is the persistent backdrop to every password-manager statistic, and the Gen Z paradox sits at its center: the cohort with the highest password-manager adoption (46%) also has the highest reuse rate (72%). 72% of Gen Z respondents reuse passwords, contrasting with only 42% of Boomers. 59% of Gen Z also reuse existing passwords when updating an account with a company that has experienced a data breach, compared to just 23% of Boomers.
A password manager is not, by itself, eliminating reuse. Gen Z appears to use a manager to store reused passwords as much as to generate unique ones.
The wider population’s behavior reinforces the gap. Approximately 23% of people reuse a password across three or four different accounts, and 30% of people whose passwords were stolen attributed the theft to reuse, per Forbes Advisor data cited by Huntress. 92% of IT professionals have admitted to reusing passwords, according to Bitwarden’s industry survey, the same workforce responsible for keeping enterprise credentials safe.
Credential channels matter too. 5.3 billion credential pairs are circulating in criminal underground sources, and exposed-password reuse compounds the risk. Phishing, including voice phishing data channels, supplies a steady stream of new credentials that recirculate when reused.
Security Outcomes: Do Password Managers Reduce Identity Theft?
Security.org’s longitudinal data shows a measurable outcome gap. Users with password managers were less likely to experience identity theft or credential theft in the past year compared with those without (17% vs. 32%). The difference roughly halves the reported incidence rate, though the comparison reflects self-selection (people who already practice good security hygiene also adopt managers).
Are password managers safe to use?
Security.org’s 2026 data shows that password-manager users report identity theft or credential theft at 17%, roughly half the 32% rate among non-users. At least 70% of security experts believe password managers are the safest choice for managing passwords, per GoodFirms data. Password managers help reduce credential-theft risk; they do not eliminate it, and a compromised master password remains a single point of failure.
| Outcome | Password-manager users | Non-users |
|---|---|---|
| Reported identity theft / credential theft (past 12 months) | 17% | 32% |
| Use unencrypted notes or paper for passwords | Lower | Over 50% |
Source: Security.org 2024 Password Manager Industry Report (updated March 2026)
The broader cybersecurity context matters too. Verizon’s 2026 DBIR found that 4% of Active Directory user accounts are using passwords already compromised elsewhere, a baseline level of exposed-credential risk that exists across most enterprises regardless of which password-management tool individual employees use. SQ Magazine’s broader cybersecurity coverage tracks the same trend across breach types.
Why Most People Still Don’t Use a Password Manager
About two-thirds of US adults still rely on memory, written notes, or browser autosave for credentials. Over half of adults use unsecured methods like memorization, browser storage, and written records to manage their passwords, and barriers are predictable: trust, perceived cost, and friction in mobile setup.
The most common barriers reported across Security.org and Bitwarden surveys:
- Trust gap. Nearly 1 in 4 people, 22%, don’t use any particular methods to keep their passwords safe, and a substantial minority of users distrust the idea of placing every password in one vault.
- Cost perception. Free browser-native managers blunt the value proposition of paid tools, even though paid plans typically run $1-$5 per user per month.
- Mobile setup friction. Password-manager autofill on mobile remains less polished than desktop; Mobile usage (phones) is now the dominant access channel for most consumer accounts, making mobile UX the decisive factor for new adopters.
- Account abandonment as workaround. 55% of respondents have abandoned an account or created a new one simply to avoid going through the password reset process, an indicator of how broken the underlying password experience still is for many users.
Why it matters: Adoption ceilings on password managers track these usability frictions more than they track awareness. With over 75% of non-users open to adoption given the right balance of usability, security, and affordability, the remaining gap is product experience, not consumer education.
Password Managers vs Browser-Stored Passwords
Browser-stored credentials remain the default for most users, and they dominate market share precisely because they are the default. Google Password Manager (browser-native) accounts for about 32% of US password-manager users by Security.org’s 2026 measurement, more than three times the share of Bitwarden or LastPass.
| Dimension | Browser-stored (Chrome / Safari) | Dedicated password manager |
|---|---|---|
| Default availability | Pre-installed | Requires install + signup |
| Cross-platform sync | Same-vendor only | Vendor-agnostic |
| Password generator | Yes (basic) | Yes (configurable) |
| Secure sharing | Limited | Yes (with audit logs in paid plans) |
| Breach monitoring | Limited (Chrome alerts) | Yes (most paid plans) |
| Recovery on master-password loss | Tied to Google / Apple ID recovery | Varies, some are zero-knowledge with no recovery |
Source: SQ Magazine analysis of Security.org 2024 report + vendor documentation
The trade-off is consistent: browser-native managers are easier to start with and harder to migrate from, while standalone managers offer cross-vendor portability and richer sharing features at the cost of one more signup. For consumers who live in a single vendor’s ecosystem, browser-native is usually adequate; for households or small teams that need to share credentials, standalone is the better fit.
The DBIR data reinforces a security parity point. In basic web application attacks, stolen credentials remain the top action, sourced from phishing, infostealers, or prior breach data bought on criminal markets; attackers exploit weak or reused credentials regardless of which manager (if any) the user picked.
Enterprise and Workplace Adoption
- Workforce adoption has moved faster than consumer adoption: 68% of organizations are deploying, piloting, or rolling out passkeys for employee authentication, according to the FIDO Alliance’s 2026 workforce survey of 1,400 enterprise decision-makers.
- Yet the cracks remain visible: just 13% of respondents report using a password manager to share credentials securely, per Bitwarden 2025.
- 92% of IT professionals have admitted to reusing passwords, per Bitwarden’s industry data.
- Verizon DBIR shows 4 in 10 corporate users have reused an exposed password.
Remote work accelerated the need for credential discipline because employees moved between personal and corporate devices without IT visibility. Password-manager rollouts in remote-first companies are higher than industry averages, although precise adoption splits by work setting are not yet broken out in any 2026 primary survey we found.
| Workforce segment | Indicator | Source |
|---|---|---|
| Enterprise (500+ employees) | 68% deploying or piloting passkeys | FIDO Alliance State of Passkeys 2026 |
| IT professionals globally | 92% admit password reuse | Bitwarden (via Huntress) |
| Corporate user base | 4 in 10 reused an exposed password | Verizon DBIR 2026 |
Source: FIDO Alliance State of Passkeys 2026, Bitwarden via Huntress, Verizon DBIR 2026
Smaller businesses face the steepest version of this gap. Small business IT teams typically lack dedicated security staff to roll out enterprise password-manager licensing, leaving SMB credentials concentrated in browser-native managers or shared spreadsheets.
Passkeys and the Future of Password Managers
Passkeys are the structural shift behind every other number in this report. 5 billion passkeys are now in active use globally, 90% of consumers are familiar with passkeys, and 75% have enabled them on at least one account, per the FIDO Alliance State of Passkeys 2026.
| Metric | Value |
|---|---|
| Global passkeys in active use | 5 billion |
| Consumer awareness | 90% |
| Consumers with at least one passkey enabled | 75% |
| Organizations deploying or piloting passkeys | 68% |
Source: FIDO Alliance State of Passkeys 2026 (n=11,000 consumers + 1,400 enterprise decision-makers, 10 countries)
FIDO Alliance research on World Passkey Day 2026 also reported that 49% of people use passkeys regularly when available, a measured-usage figure that lags the 75%-enabled headline. The gap between “enabled” and “regularly use” is the same shape as the gap between password-manager adoption and consistent unique-password behavior; enabling a feature is not the same as relying on it.
Most passkeys ride on the same Apple and Google rails that already dominate password-manager market share. The consumer research involved 11,000 adults across the United States, United Kingdom, France, Germany, Australia, Singapore, Japan, South Korea, China, and India, giving a cross-region read on awareness, high in every country, with regular use trailing in markets where enterprise rollouts are still early.
The takeaway: Passkeys are not replacing password managers in 2026, they are extending them. Most consumer passkeys sit inside the same vault (Google, Apple, 1Password, Bitwarden) that already holds the user’s passwords. The password manager is becoming the credential manager, and the trajectory of one tracks the trajectory of the other.
Password Manager Breaches and Regulatory Action
The UK Information Commissioner’s Office fined LastPass UK Ltd £1.2 million in December 2025 for the 2022 data breach that compromised personal information on up to 1.6 million UK customers. The ICO said the service had “promises to help people improve their security” but “failed them, leaving them vulnerable” in its enforcement statement.
| 2026 DBIR finding | Value |
|---|---|
| Credential abuse share of breaches | 13% |
| Vulnerability exploitation share | 31% |
| Credential pairs circulating on criminal markets | 5.3 billion |
| Corporate users who reused an exposed password | 4 in 10 |
| AD accounts using a previously compromised password | 4% |
| Years credential theft topped initial-access ranking before 2026 | 19 |
Source: Verizon 2026 Data Breach Investigations Report
Verizon found vulnerability exploitation overtook credential abuse as the dominant initial access vector at 31% versus 13% for credential abuse, the first time in 19 years that credential theft is not at the top. Independent coverage of the same Verizon report noted that credential abuse decline reflects broader MFA and password-manager adoption, although infostealer malware and prior-breach data continue to feed cybersecurity attacks data on basic web applications.
Generative AI is accelerating attacks, with threat actors applying AI across an average of 15 distinct attack techniques, according to the same DBIR, a tailwind for phishing and credential-harvesting campaigns that password-manager autofill protections can mitigate but not eliminate.
The ICO action against LastPass signals that UK regulators now treat password-manager providers as fiduciaries, the same legal posture that governs banks and identity-verification platforms.
Password Manager Pricing and Market Size
Industry estimates size the global password management market at approximately $3.79 billion for 2026, projected to reach about $10.63 billion by 2034 at a compound annual growth rate around 13.77%. SQ Magazine does not link the market-research seller behind the figure.
Consumer pricing remains roughly stable across major vendors. Most major paid managers offer free tiers, with the price floor set by Google’s and Apple’s free, OS-integrated services. Paid offerings differentiate on cross-platform sync, sharing, and breach monitoring rather than on price.
Over 75% of non-users say they are open to adopting a password manager if it offers the right combination of usability, security, and affordability, an addressable ceiling that the current pricing structure does not fully unlock because the friction is in setup and mobile experience, not in monthly cost.
Conclusion
This year’s password-manager picture compresses two competing trajectories into a single category. Password-manager adoption among US adults sits at 36%, about 94 million users, and rose 2 percentage points in the latest Security.org cycle. At the same time, 5 billion passkeys are already in active use globally per the FIDO Alliance, and the rails carrying that growth belong overwhelmingly to Google and Apple, which together control over 55% of the US password-manager market through their proprietary services.
The trust-and-use gap is the binding constraint through the rest of this decade. Security.org’s data shows over 75% of non-users would consider a password manager with the right balance of usability, security, and affordability. The UK ICO fined LastPass UK Ltd £1.2 million in December 2025 over the 2022 data breach that exposed personal information of 1.6 million customers. The next wave of users will arrive through better mobile setup and clearer breach accountability, not through new technology.