惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
I
InfoQ
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
Y
Y Combinator Blog
博客园_首页
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
C
Check Point Blog
B
Blog RSS Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Engineering at Meta
Engineering at Meta
B
Blog
爱范儿
爱范儿
Stack Overflow Blog
Stack Overflow Blog
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
F
Fortinet All Blogs
月光博客
月光博客
GbyAI
GbyAI

WeLiveSecurity

Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan
Old habits die hard: 2025’s most common passwords were as...
Christian Ali Bravo · 2026-01-20 · via WeLiveSecurity

Digital Security

Once again, data shows an uncomfortable truth: the habit of choosing eminently hackable passwords is alive and well

20 Jan 2026  •  , 3 min. read

Old habits die hard: 2025’s most common passwords were as predictable as ever

‘123456’ continues to reign supreme as the most commonly-used password among people across the world, according to two reports, from NordPass and Comparitech, respectively. A full 25 percent of the top 1,000 most-used passwords are made up of nothing but numerals.

In addition, ‘123456’ appealed to people of various age cohorts, as it was the most-favored option among millennials, Generation X and baby boomers alike, and the second most-popular option among Generation Z and the Silent Generation (after ‘12345’). This is according to NordPass’ analysis, which is based on billions of leaked passwords and sheds light on password trends among people in 44 countries.  

Another all-too-predictable choice, ‘admin’, trailed close behind, with ‘12345678’, ‘123456789’ and ‘12345’ coming next, as many people clearly continue to favor convenience, putting their personal data, money and possibly reputations at risk.

most-common-passwords-2025
The top 10 most common passwords among people in 44 countries (source: NordPass)

In the US and the UK, the overall picture was just as grim, with ‘admin’ taking the top spot in both countries. In the US, the one and only ‘password’ and ‘123456’ took the second and third spots, respectively; in the UK, the two just swapped places.

Much the same picture is painted by Comparitech’s research into two billion real account passwords leaked on data breach forums in 2025, as it had ‘123456’, ‘12345678’ and ‘123456789’ atop its list.

Same old, same old

Using an easily-guessable password is tantamount to locking the front door of your house with a paper latch. It offers no actual resistance, and attackers can use brute-force or credential stuffing techniques that allow them to make quick work of such weak or reused passwords at scale.

It goes without saying, therefore, that if your password made it among those most common password choices, you would be very well advised to change it immediately. Use a strong and unique password or passphrase for each account and ideally, store them in a reputable password manager.

No matter how stubborn, however, a password is still only a single barrier between your account and a hacker. That’s why two-factor authentication (2FA) as an extra layer of security is a non-negotiable line of defense these days, particularly for accounts that contain Personally Identifiable Information (PII) or other important data.

The risks rise sharply in corporate environments. Weak, obvious, or reused passwords can expose not only individual employees, but entire organizations, their customers, and their partners. Indeed, in many cases, the initial point of entry is neither sophisticated nor novel; instead, it’s simply a password that should never have been trusted in the first place. The consequences, meanwhile, are rarely trivial and span financial loss, operational disruption, regulatory scrutiny, and long-term reputational damage. Which is why companies need a combination of technical safeguards and ongoing security awareness training programs for employees.

Meanwhile, the technical barriers for ne’er-do-wells have never been lower. Modern tools can test countless combinations of login credentials in minutes, so the odds are firmly stacked in the attacker’s favor. Plus, in the digital ecosystem built on interconnected services and shared identities, the damage stemming from one account takeover is unlikely to stay contained for long.

Also, passkeys are rapidly becoming commonplace, and many major platforms, including Apple, Google, and Amazon, now offer them as a primary login method.

You might have had many New Year’s resolutions heading into 2026. But if your own passwords appear on either list above, improving your account security should be one of the most important of them.


Let us keep you
up to date

Sign up for our newsletters