Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Tips and Advice»2025’s most common passwords were as predictable as ever
Tips and Advice

2025’s most common passwords were as predictable as ever

Team-CWDBy Team-CWDJanuary 21, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Once again, data shows an uncomfortable truth: the habit of choosing eminently hackable passwords is alive and well

‘123456’ continues to reign supreme as the most commonly-used password among people across the world, according to two reports, from NordPass and Comparitech, respectively. A full 25 percent of the top 1,000 most-used passwords are made up of nothing but numerals.

In addition, ‘123456’ appealed to people of various age cohorts, as it was the most-favored option among millennials, Generation X and baby boomers alike, and the second most-popular option among Generation Z and the Silent Generation (after ‘12345’). This is according to NordPass’ analysis, which is based on billions of leaked passwords and sheds light on password trends among people in 44 countries.  

Another all-too-predictable choice, ‘admin’, trailed close behind, with ‘12345678’, ‘123456789’ and ‘12345’ coming next, as many people clearly continue to favor convenience, putting their personal data, money and possibly reputations at risk.

most-common-passwords-2025
The top 10 most common passwords among people in 44 countries (source: NordPass)

In the US and the UK, the overall picture was just as grim, with ‘admin’ taking the top spot in both countries. In the US, the one and only ‘password’ and ‘123456’ took the second and third spots, respectively; in the UK, the two just swapped places.

Much the same picture is painted by Comparitech’s research into two billion real account passwords leaked on data breach forums in 2025, as it had ‘123456’, ‘12345678’ and ‘123456789’ atop its list.

Same old, same old

Using an easily-guessable password is tantamount to locking the front door of your house with a paper latch. It offers no actual resistance, and attackers can use brute-force or credential stuffing techniques that allow them to make quick work of such weak or reused passwords at scale.

It goes without saying, therefore, that if your password made it among those most common password choices, you would be very well advised to change it immediately. Use a strong and unique password or passphrase for each account and ideally, store them in a reputable password manager.

No matter how stubborn, however, a password is still only a single barrier between your account and a hacker. That’s why two-factor authentication (2FA) as an extra layer of security is a non-negotiable line of defense these days, particularly for accounts that contain Personally Identifiable Information (PII) or other important data.

The risks rise sharply in corporate environments. Weak, obvious, or reused passwords can expose not only individual employees, but entire organizations, their customers, and their partners. Indeed, in many cases, the initial point of entry is neither sophisticated nor novel; instead, it’s simply a password that should never have been trusted in the first place. The consequences, meanwhile, are rarely trivial and span financial loss, operational disruption, regulatory scrutiny, and long-term reputational damage. Which is why companies need a combination of technical safeguards and ongoing security awareness training programs for employees.

Meanwhile, the technical barriers for ne’er-do-wells have never been lower. Modern tools can test countless combinations of login credentials in minutes, so the odds are firmly stacked in the attacker’s favor. Plus, in the digital ecosystem built on interconnected services and shared identities, the damage stemming from one account takeover is unlikely to stay contained for long.

Also, passkeys are rapidly becoming commonplace, and many major platforms, including Apple, Google, and Amazon, now offer them as a primary login method.

You might have had many New Year’s resolutions heading into 2026. But if your own passwords appear on either list above, improving your account security should be one of the most important of them.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePhishing and Spoofed Sites Remain Primary Entry Points For Olympics
Next Article Peruvian Loan Scam Harvests Cards and PINs via Fake Applications
Team-CWD
  • Website

Related Posts

Tips and Advice

A phishing attack that doesn’t steal your password

June 15, 2026
Tips and Advice

Why children’s data is a long-term identity risk

June 3, 2026
Tips and Advice

What to consider before asking an AI chatbot for health advice

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Children and chatbots: What parents should know

January 23, 2026

What parents should know to protect their children from doxxing

November 28, 2025

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.