Most people reuse the same three awful passwords - here's why that's a problem

passwords
(Image credit: italii Vodolazskyi / Shutterstock)

A survey of UK citizens has revealed a range of poor cybersecurity practices that could expose both personal and corporate data.

According to TheHackShield, people often reuse the same password across multiple services, create passwords that are relatively easy to guess with a little social engineering, and will wait for years before updating account credentials.

The cybersecurity firm recently polled 2,200 UK adults and discovered that two-thirds of people use just three passwords across all their online accounts, of which there are usually about 50. Almost half of the respondents (48%) use the same password for both personal and professional services.

Drilling deeper into their most popular choices, street names (20%), pet names (15%) and special dates (14%) were the most common passwords - all of which can be obtained relatively easily via social engineering.

Only 5% of people regularly update the passwords on their key accounts, in order to remain secure. The rest take seven years on average to change a password and, when they do it, it’s often due to “clear signs of hacking”.

Even when they are warned about poor cybersecurity hygiene, most people don’t do much about it. The majority (71%) of iPhone owners ignore alerts designed to notify the user if a password has been compromised in a data breach.

Keeping old passwords is risky

Although convenience likely factors into this behavior, the report found that most (51%) are afraid they will forget new passwords, while some (29%) said they couldn’t think of anything secure enough.

Commenting on the report, Nikhil S. Mahadeshwar, co-founder and CTO at Skynet Softtech, explained why it’s essential to regularly update passwords:

“Changing your password regularly is vital to staying safe online. Changing your password once a month will help to dramatically reduce your chances of becoming a victim of hacking," he said.

"You can also use two-step authentication and RSA hardware token, which looks like a flash drive to safeguard your password.  Whenever you get a notification or alert to change your password, do so immediately, otherwise, your valuable information could fall into the wrong hands.”

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
password manager
I'm a security expert - here are my biggest tips for creating a secure password for work and home life to stay safe online
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
A digital representation of a lock
Gen Z and Millennial social media accounts are ripe for the taking and this doesn’t surprise me
Young woman working at a coffee shop with a laptop
Too many passwords, not enough brain space? Here’s how password managers can improve your life
Man screaming at computer with TechRadar data privacy week logo next to it.
I almost lost my entire online identity – until one tool made all the difference
Holographic representation of cloud computing over open businessman's hand
AWS, Azure and Google Cloud credentials from old accounts are putting businesses at risk
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day