As soon as once more, knowledge exhibits an uncomfortable reality: the behavior of selecting eminently hackable passwords is alive and properly
20 Jan 2026
•
,
3 min. learn

‘123456’ continues to reign supreme as probably the most commonly-used password amongst folks internationally, in accordance with two reviews, from NordPass and Comparitech, respectively. A full 25 p.c of the highest 1,000 most-used passwords are made up of nothing however numerals.
As well as, ‘123456’ appealed to folks of varied age cohorts, because it was the most-favored possibility amongst millennials, Technology X and child boomers alike, and the second most-popular possibility amongst Technology Z and the Silent Technology (after ‘12345’). That is in accordance with NordPass’ evaluation, which is predicated on billions of leaked passwords and sheds gentle on password traits amongst folks in 44 nations.
One other all-too-predictable selection, ‘admin’, trailed shut behind, with ‘12345678’, ‘123456789’ and ‘12345’ coming subsequent, as many individuals clearly proceed to favor comfort, placing their private knowledge, cash and probably reputations in danger.

Within the US and the UK, the general image was simply as grim, with ‘admin’ taking the highest spot in each nations. Within the US, the one and solely ‘password’ and ‘123456’ took the second and third spots, respectively; within the UK, the 2 simply swapped locations.
A lot the identical image is painted by Comparitech’s analysis into two billion actual account passwords leaked on knowledge breach boards in 2025, because it had ‘123456’, ‘12345678’ and ‘123456789’ atop its record.
Usual, standard
Utilizing an easily-guessable password is tantamount to locking the entrance door of your home with a paper latch. It affords no precise resistance, and attackers can use brute-force or credential stuffing methods that permit them to make fast work of such weak or reused passwords at scale.
It goes with out saying, subsequently, that in case your password made it amongst these commonest password selections, you’d be very properly suggested to change it instantly. Use a powerful and distinctive password or passphrase for every account and ideally, retailer them in a good password supervisor.
Irrespective of how cussed, nonetheless, a password remains to be solely a single barrier between your account and a hacker. That’s why two-factor authentication (2FA) as an additional layer of safety is a non-negotiable line of protection nowadays, significantly for accounts that include Personally Identifiable Data (PII) or different vital knowledge.
The dangers rise sharply in company environments. Weak, apparent, or reused passwords can expose not solely particular person workers, however total organizations, their prospects, and their companions. Certainly, in lots of circumstances, the preliminary level of entry is neither subtle nor novel; as a substitute, it’s merely a password that ought to by no means have been trusted within the first place. The results, in the meantime, are hardly ever trivial and span monetary loss, operational disruption, regulatory scrutiny, and long-term reputational injury. Which is why firms want a mixture of technical safeguards and ongoing safety consciousness coaching packages for workers.
In the meantime, the technical obstacles for ne’er-do-wells have by no means been decrease. Trendy instruments can check numerous combos of login credentials in minutes, so the chances are firmly stacked within the attacker’s favor. Plus, within the digital ecosystem constructed on interconnected companies and shared identities, the injury stemming from one account takeover is unlikely to remain contained for lengthy.
Additionally, passkeys are quickly turning into commonplace, and plenty of main platforms, together with Apple, Google, and Amazon, now provide them as a main login technique.
You may need had many New 12 months’s resolutions heading into 2026. But when your personal passwords seem on both record above, bettering your account safety must be one of the vital vital of them.










