2025's Most Common Passwords Remain Predictably Weak, Security Reports Warn
Recent analyses by NordPass and Comparitech reveal that insecure password habits persist globally in 2025, with '123456' remaining the most commonly used password worldwide. The reports, based on billions of leaked credentials from 44 countries, highlight that twenty-five percent of the top 1,000 passwords consist entirely of numbers. While '123456' dominated across Millennials, Generation X, and Baby Boomers, 'admin' was the most frequent choice in the US and UK. Other prevalent weak passwords include '12345678', '123456789', and 'password'. Cybersecurity experts warn that such predictable choices leave users vulnerable to brute-force attacks and credential stuffing, risking personal data, financial assets, and reputations. The article emphasizes the critical need for individuals to adopt strong, unique passwords managed via reputable password managers and to enable two-factor authentication (2FA). For corporations, weak passwords pose significant risks, including operational disruption and regulatory scrutiny, necessitating robust security awareness training. As technical barriers for attackers lower, the adoption of passkeys by major platforms like Apple and Google is presented as a viable, more secure alternative to traditional passwords for protecting digital identities.
Wire timeline
2025's Most Common Passwords Remain Predictably Weak, Security Reports Warn
Recent analyses by NordPass and Comparitech reveal that insecure password habits persist globally in 2025, with '123456' remaining the most commonly used password worldwide. The reports, based on billions of leaked credentials from 44 countries, highlight that twenty-five percent of the top 1,000 passwords consist entirely of numbers. While '123456' dominated across Millennials, Generation X, and Baby Boomers, 'admin' was the most frequent choice in the US and UK. Other prevalent weak passwords include '12345678', '123456789', and 'password'. Cybersecurity experts warn that such predictable choices leave users vulnerable to brute-force attacks and credential stuffing, risking personal data, financial assets, and reputations. The article emphasizes the critical need for individuals to adopt strong, unique passwords managed via reputable password managers and to enable two-factor authentication (2FA). For corporations, weak passwords pose significant risks, including operational disruption and regulatory scrutiny, necessitating robust security awareness training. As technical barriers for attackers lower, the adoption of passkeys by major platforms like Apple and Google is presented as a viable, more secure alternative to traditional passwords for protecting digital identities.
WeLiveSecurity