The most common passwords in the world can be cracked in under a second

password manager security
(Image credit: Passwork)

It looks like that many of us spent 2023 using the weakest passwords possible for our online accounts, putting us all at risk of being hacked in the blink of an eye. 

New research from password manager NordPass discovered the top 200 most common passwords in the world for this year - 70% of which are so poor that they can be cracked in under a second. 

The study also looked into what passwords are used for certain accounts, finding that those securing a users' financial accounts are the strongest, whereas those used for streaming service accounts are the weakest. 

Lessons not learned

The list was compiled from a 4.3TB database populated from various publicly available sources, such as passwords that have been leaked on the dark web. The most common password globally was '123456', followed by 'admin'. Almost a third of all passwords in the list used some kind of numerical sequence. 

For four years out of the previous five, '123456' has taken the number one spot. It is also the popular used in the US this year, which marks a change from last year, where the nation's favorite was 'guest', an equally weak password.

Users around the world also created passwords that reference certain brands or companies relevant to the type of account they are securing. For instance, passwords such as 'iPhone6s' and 'Samsung1' were commonly used for smartphone apps. 

'admin' also made it near the top in each of the 30 countries looked at this year, suggesting that people aren't bothering to change default passwords as they should.

NordPass notes that with the increasing threat of infostealing malware, using strong passwords and protecting them properly is more important than ever. CTO Tomas Smalakys commented that, "alternative methods in online authentication are now essential." 

He added that passkeys, the new passwordless technology, are the future to securing online accounts, as they are "considered the most promising innovation to replace passwords... gaining trust among individuals and progressive companies worldwide." 

"Being among the first password managers to offer this technology, we see people are curious to test new things, as long as this helps eliminate the hassle of passwords.”

MORE FROM TECHRADAR PRO

Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
password manager
I'm a security expert - here are my biggest tips for creating a secure password for work and home life to stay safe online
Young woman working at a coffee shop with a laptop
Too many passwords, not enough brain space? Here’s how password managers can improve your life
Man screaming at computer with TechRadar data privacy week logo next to it.
I almost lost my entire online identity – until one tool made all the difference
A digital representation of a lock
Gen Z and Millennial social media accounts are ripe for the taking and this doesn’t surprise me
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
LastPass 2022 hack fallout continues with millions of dollars more reportedly stolen
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Close up of PS5 DualSense controller leaning on a PS5
Sony goes full Xbox Insider with new Beta Program at PlayStation initiative, offering the testing of new games and features before release
Artificial Intelligence
Amazon is apparently going all-in on agentic AI
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop