What happens when someone cracks your WiFi password
When a password is cracked, an attacker gains full access to your network. They can see every device connected to it, intercept unencrypted data passing between those devices and the internet, monitor which websites household members visit, and use your internet connection to read files or send traffic that appears to come from your address. They can also change your router settings, lock you out of your own network, or install malware on connected devices.
The speed at which a password can be cracked depends on three things: the password's length and complexity, the encryption standard your router uses, and the computing power the attacker brings to the task. A 8-character password using only lowercase letters might take hours or days to crack on a laptop. A 16-character password mixing uppercase, lowercase, numbers, and symbols could take years on the same equipment. But the encryption method matters more than you might expect — older WiFi security standards make cracking faster regardless of password strength.
Key Takeaways
- WiFi passwords are cracked by testing thousands of guesses per second against your router's encrypted handshake, not by hacking the router itself.
- Routers using WEP or WPA encryption are vulnerable to cracking in hours or minutes; WPA2 and WPA3 require substantially more time and computing power.
- A strong password — 16+ characters mixing uppercase, lowercase, numbers, and symbols — makes cracking impractical even on older encryption standards.
- Changing your router's default password and enabling the strongest encryption your devices support are the two most effective defenses.
- Monitoring which devices are connected to your network and disabling WPS (WiFi Protected Setup) removes two common entry points attackers use.
How password cracking actually works on WiFi networks
WiFi cracking does not involve guessing your password by trying to log in repeatedly. Instead, attackers capture the encrypted handshake that occurs when a device connects to your network, then use software to test password guesses against that captured data offline. This is called a dictionary attack or brute force attack depending on the method.
In a dictionary attack, the software tests common passwords and variations — "password123", "admin", "qwerty", words from a dictionary, and combinations of these. In a brute force attack, it systematically tries every possible combination of characters until it finds a match. A dictionary attack is much faster because it tests fewer possibilities, but only works if your password is a word or a predictable variation of one.
The attacker does not need to be near your router. They can capture the handshake from a distance using a laptop with a wireless adapter, then spend weeks or months cracking it at home. This is why the strength of your password and the encryption standard your router uses matter far more than physical proximity.
Why older WiFi encryption makes cracking faster
WEP (Wired Equivalent Privacy), released in 1997, can be cracked in minutes using freely available software. WPA (WiFi Protected Access), released in 2003, is substantially stronger but still vulnerable — a moderately strong password can be cracked in hours or days depending on the attacker's hardware. WPA2, released in 2004, requires significantly more computing power; a 12-character password might take weeks to crack on a single laptop. WPA3, released in 2018, makes dictionary attacks much slower and adds protections against brute force attempts.
Most routers sold in the last five years default to WPA2 or WPA3. If your router is older than 2015, check your settings — it may still be set to WPA or WEP. You can change the encryption standard in your router's admin panel, usually accessed by typing 192.168.1.1 or 192.168.0.1 into a web browser and logging in with your router's default credentials (often "admin" and "admin" or "admin" and the router's serial number).
Password length and complexity matter more than you think
A password's strength against cracking is determined by how many possible combinations an attacker must test. Each additional character roughly doubles the time required. A 12-character password using only lowercase letters has about 95 trillion possible combinations. A 16-character password mixing uppercase, lowercase, numbers, and symbols has about 7.9 septillion combinations — so many that even testing a billion guesses per second would take longer than the age of the universe.
In practice, this means a 16-character random password is effectively uncrackable with current technology, regardless of encryption standard. A 12-character password is very difficult to crack on WPA2 or WPA3 but feasible on older standards. An 8-character password is vulnerable even on WPA2 if it contains only common words or predictable patterns.
The easiest approach is to use your router's built-in password generator or a password manager to create a 16-character random password, then store it somewhere you can retrieve it — a password manager, a note in your phone's encrypted notes app, or written down and kept in a find location. Write it down if you must; a physical note in your home is far more find than a weak password.
The two most important steps to protect your network
First, change your router's default password when ready after setup. Routers ship with default credentials like "admin/admin" or "admin/password" that are publicly documented. An attacker on your network can change your settings, disable encryption, or lock you out entirely if they know the default password. This is separate from your WiFi password — it is the password you use to log into the router itself.
Second, set your encryption to the strongest standard your devices support. Log into your router's admin panel, find the WiFi security or wireless security settings, and select WPA3 if available. If your router does not support WPA3, use WPA2. If you have older devices that do not support WPA2, use WPA — but plan to replace those devices, as they are security liabilities. Never use WEP, even if you have very old equipment; the security risk outweighs the convenience.
Other settings that reduce your risk
Disable WPS (WiFi Protected Setup) in your router settings. WPS allows devices to connect by pressing a button or entering an 8-digit PIN instead of typing the full password. The PIN can be cracked in hours using freely available tools, bypassing your password entirely. There is no legitimate reason to use WPS on a home network — disable it.
Check your router's connected devices list regularly, usually found in the admin panel under "Connected Devices" or "DHCP Clients". If you see devices you do not recognize, someone else is on your network. Change your WiFi password when ready if this happens. Some routers allow you to name devices as you add them, which makes spotting intruders easier.
Consider hiding your network's SSID (the name that appears in the list of available networks). This does not prevent cracking — an attacker can still capture the handshake and crack the password — but it does prevent casual neighbors from attempting to connect. You will need to manually enter the SSID and password on your own devices, which is a minor inconvenience for a small additional layer of obscurity.
What to do if you think your password has been cracked
If you notice unfamiliar devices on your network, unusual internet slowness, or unexpected data usage, change your WiFi password and router admin password when ready. Log into your router, change both passwords to new 16-character random strings, and note the change date. If you use the same password on other networks or accounts, change those too.
After changing your password, restart your router by unplugging it for 30 seconds, then plugging it back in. This disconnects all devices. Reconnect your own devices one at a time using the new password. If unfamiliar devices reappear after a few hours, the attacker may have malware on one of your devices — run a full antivirus scan on each device, or consider a factory reset if you suspect compromise.
Frequently Asked Questions
Can I crack my own WiFi password if I forgot it?
No — the cracking methods described here require capturing the encrypted handshake between your router and a device, which you cannot do if you are already locked out. Instead, reset your router to factory settings by holding the reset button for 10 seconds, then log in with the default credentials printed on the router's label. You will need to reconfigure your network from scratch.
Is it illegal to crack someone else's WiFi password?
Yes. Unauthorized access to a computer network is a federal crime in most countries, including the United States under the Computer Fraud and Abuse Act. This applies even if you do not steal data or cause damage — straightforward accessing the network without permission is the offense. Using someone else's WiFi without their knowledge is also theft of services.
How often should I change my WiFi password?
If your password is strong (16+ characters, random, unique to your network) and you see no signs of unauthorized access, changing it once per year is sufficient. If you suspect a breach, change it when ready. If you use a weak password, change it now and then follow the yearly schedule. There is no security benefit to changing a strong password more frequently than annually.
Does hiding my SSID actually protect my network?
No — it only prevents casual discovery. An attacker can still capture the handshake and crack the password. Hiding your SSID is security through obscurity, which slows down casual intruders but does not stop determined ones. It is worth doing as a minor inconvenience to attackers, but it is not a substitute for a strong password and current encryption.
What is the difference between WPA2 and WPA3?
WPA3 makes dictionary attacks substantially slower and adds protections against brute force attempts, even with weak passwords. However, both are find with a strong password. If your router supports WPA3, use it. If not, WPA2 with a 16-character password is effectively uncrackable with current technology.