During the first six months of 2019, more than 4 billion records were exposed by data breaches. That's a shocking statistic that's made even more so when you realize that passwords were included in droves. On December 4, a security researcher discovered a treasure trove of more than a billion plain-text passwords in an unsecured online database.
Now researchers at NordPass, a password manager from the people who are behind the NordVPN app, have set about ranking the most used and least secure passwords. Armed with a database of some 500 million passwords leaked as a result of data breaches in 2019, NordPass researchers were able to rank them in order of usage.
Password hygiene is a top security priority
The top three most commonly used passwords, notching up 6,348,704 appearances between them, are shockingly insecure, weak, and totally predictable. However, there are also many unexpected passwords on the list and that's the worrying thing. Well, worrying if you happen to be using any of them, that is. If a password you use is on the list, then your security posture has just been weakened. Hackers can brute-force their way into accounts by throwing known common passwords, as well as dictionary words, at them. If you use the same password across multiple sites and services, then your security posture is so bad you urgently need to see a cyber-chiropractor. As I reported on December 6, Microsoft analyzed a database of 3 billion leaked credentials from security breaches and found that more than 44 million Microsoft accounts were using passwords that had already been compromised elsewhere. Password reuse is a sure-fire way to get yourself, your accounts and your data into trouble, especially if you are using one of the world's worst passwords.
Ranked: the world's 100 worst passwords
You can find the full listing of the world's worst passwords, together with usage statistics, in the NordPass report. Here are just the top 100 worst passwords. If any of them look at all familiar, go and change the respective account login credentials immediately.
- 12345
- 123456
- 123456789
- test1
- password
- 12345678
- zinch
- g_czechout
- asdf
- qwerty
- 1234567890
- 1234567
- Aa123456.
- iloveyou
- 1234
- abc123
- 111111
- 123123
- dubsmash
- test
- princess
- qwertyuiop
- sunshine
- BvtTest123
- 11111
- ashley
- 00000
- 000000
- password1
- monkey
- livetest
- 55555
- soccer
- charlie
- asdfghjkl
- 654321
- family
- michael
- 123321
- football
- baseball
- q1w2e3r4t5y6
- nicole
- jessica
- purple
- shadow
- hannah
- chocolate
- michelle
- daniel
- maggie
- qwerty123
- hello
- 112233
- jordan
- tigger
- 666666
- 987654321
- superman
- 12345678910
- summer
- 1q2w3e4r5t
- fitness
- bailey
- zxcvbnm
- fuckyou
- 121212
- buster
- butterfly
- dragon
- jennifer
- amanda
- justin
- cookie
- basketball
- shopping
- pepper
- joshua
- hunter
- ginger
- matthew
- abcd1234
- taylor
- samantha
- whatever
- andrew
- 1qaz2wsx3edc
- thomas
- jasmine
- animoto
- madison
- 0987654321
- 54321
- flower
- Password
- maria
- babygirl
- lovely
- sophie
- Chegg123