Even Fortune 500 businesses have poor password hygiene

Passwords
(Image credit: Shutterstock)

When it comes to password hygiene and security, even Fortune 500 businesses don't use secure passwords according to new research from NordPass.

To compile it's new Fortune 500 password study, the researchers at the password management company analyzed data from public third-party breaches that affected Fortune 500 companies. In total, they analyzed data from over 15m breaches across 17 different industries to find the top 10 passwords used in each industry, the percentile of unique passwords and the number of data breaches affecting each industry.

While using simple passwords poses a risk to all users, businesses and their employees have a lot more to lose from reusing passwords across their online accounts. Back in February for instance, a water treatment facility in Florida had a serious security breach due to the fact that it was still using Windows 7 with no firewall and all of its employees shared the same TeamViewer password.

Security expert at NordPass, Chad Hammond provided further insight on how weak employee passwords can jeopardize an organization's entire business, saying: 

“Businesses and their employees have a duty to protect their customers’ data. A weak password of one employee could potentially jeopardize the whole company if an attacker used the breached password to gain access to sensitive data.” 

Poor password hygiene

According to NordPass' research, the top password in the retail and ecommerce, energy, technology, financial services, agriculture, media and advertising, hospitality, human resources and real estate industries is “password”. While “123456” is the most popular password in telecommunications and healthcare, many other industries simply use their “company name” as their password.

Simple passwords can easily lead to data breaches and according to a report from IBM, the average global cost of a data breach is now at $3.86m. However, a data breach in the healthcare industry costs much more at $7.13m and data breaches at US-based companies now cost an average of $8.64m.

To improve password hygiene at businesses, NordPass recommends that they create complex and unique passwords using a password generator or password manager, use multi-factor authentication and educate their employees on the risks of using simple password for their work and personal accounts.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
password manager
I'm a security expert - here are my biggest tips for creating a secure password for work and home life to stay safe online
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
A digital representation of a lock
Gen Z and Millennial social media accounts are ripe for the taking and this doesn’t surprise me
Young woman working at a coffee shop with a laptop
Too many passwords, not enough brain space? Here’s how password managers can improve your life
API
Businesses are being plagued by API security risks - with nearly 99% affected
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why
Nintendo x Seattle Mariners partnership
The Nintendo Switch 2 logo will be featured on the Seattle Mariners' baseball jerseys this season
Apple iPhone 16 Pro Max Review
Siri's chances to beat ChatGPT just got a whole lot better
Acer Chromebook Plus line
Chromebooks aren't dead! Acer has just launched 7 new ChromeOS laptops aimed at students and professionals