Despite all the new forms of cyberattack, all the complex vulnerabilities, and all the elaborate social engineering techniques leveraged by threat actors, the perennial bugbear of the security professional remains the same as it ever has: weak passwords. Despite decades of education and extensive enforcement policies, simple and easily guessable passwords remain the word. Two recent reports from NortPass and Comparitech listing the top 1000 most-used passwords illustrate the case. Among the most serious issues is that a full 25 percent of those passwords consisted of nothing but numerals, making them easily guessable.
Globally, “123456” held the position as the most commonly used password, with other low-entropy choices such as “admin”, “12345678”, “123456789”, and “12345” appearing frequently among the top entries. The pattern persists across age cohorts and specific countries. In NordPass’ dataset covering 44 countries, “123456” was the most preferred option among several age groups, and “admin” followed close behind. In the United States and the United Kingdom, “admin” was the most common password, with subtle variations in rankings for “password” and numeric sequences. Comparitech’s analysis of more than two billion leaked real account passwords reinforced these findings, with similar top rankings dominated by “123456” and other short number strings. Other common passwords included “password,” “Aa123456,” and “Pass@123,” each of which had millions of accounts using it.
From an organizational perspective, weak passwords pose significant risks beyond individual accounts. In corporate environments, obvious or reused passwords can provide attackers with an initial foothold that leads to broader compromise, operational disruption, financial loss, regulatory scrutiny, and reputational damage. It is for reasons such as this that a growing number of enterprises are embracing fully passwordless authentication, making use of multifactor authentication-based tools such as mobile passkeys and biometric authentication.