{"id":8901,"date":"2026-01-20T12:00:00","date_gmt":"2026-01-20T10:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/?p=8901"},"modified":"2026-06-14T19:56:53","modified_gmt":"2026-06-14T16:56:53","slug":"old-habits-die-hard-2025s-most-common-passwords-were-as-predictable-as-ever","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2026\/01\/20\/old-habits-die-hard-2025s-most-common-passwords-were-as-predictable-as-ever\/","title":{"rendered":"Old habits die hard: 2025\u2019s most common passwords were as predictable as ever"},"content":{"rendered":"<p>\u2018123456\u2019 continues to reign supreme as the most commonly-used password among people across the world, according to two reports, from <a href=\"https:\/\/nordpass.com\/most-common-passwords-list\/\">NordPass<\/a> and <a href=\"https:\/\/www.comparitech.com\/news\/minecraft-qwerty-and-india123-among-2025s-most-common-passwords-report\/\">Comparitech<\/a>, respectively. A full 25 percent of the top 1,000 most-used passwords are made up of nothing but numerals.<\/p>\n<p>In addition, \u2018123456\u2019 appealed to people of various age cohorts, as it was the most-favored option among millennials, Generation X and baby boomers alike, and the second most-popular option among Generation Z and the Silent Generation (after \u201812345\u2019). This is according to NordPass\u2019 analysis, which is based on billions of leaked passwords and sheds light on password trends among people in 44 countries. <\/p>\n<p>Another all-too-predictable choice, \u2018admin\u2019, trailed close behind, with \u201812345678\u2019, \u2018123456789\u2019 and \u201812345\u2019 coming next, as many people clearly continue to favor convenience, putting their personal data, money and possibly reputations at risk.<\/p>\n<figure><img decoding=\"async\" alt=\"most-common-passwords-2025\" height=\"\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/01-26\/most-common-passwords-2025.png\" title=\"The top 10 most common passwords among people in 44 countries (source: NordPass)\" width=\"\"><figcaption>The top 10 most common passwords among people in 44 countries (source: <a href=\"https:\/\/nordpass.com\/most-common-passwords-list\/\">NordPass<\/a>)<\/figcaption><\/figure>\n<p>In the US and the UK, the overall picture was just as grim, with \u2018admin\u2019 taking the top spot in both countries. In the US, the one and only \u2018password\u2019 and \u2018123456\u2019 took the second and third spots, respectively; in the UK, the two just swapped places.<\/p>\n<p>Much the same picture is painted by Comparitech\u2019s research into two billion real account passwords leaked on data breach forums in 2025, as it had \u2018123456\u2019, \u201812345678\u2019 and \u2018123456789\u2019 atop its list.<\/p>\n<h2>Same old, same old<\/h2>\n<p>Using an easily-guessable password is tantamount to locking the front door of your house with a paper latch. It offers no actual resistance, and attackers can use brute-force or <a href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/credential-stuffing-what-it-is-how-protect-yourself\/\">credential stuffing<\/a> techniques that allow them to make quick work of such weak or reused passwords at scale.<\/p>\n<p>It goes without saying, therefore, that if your password made it among those most common password choices, you would be very well advised to <a href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/how-often-should-change-passwords\/\">change it immediately<\/a>. Use a strong and unique password or passphrase for each account and ideally, store them in a reputable password manager.<\/p>\n<\/p>\n<p>No matter how stubborn, however, a password is still only a single barrier between your account and a hacker. That\u2019s why two-factor authentication (2FA) as an extra layer of security is a non-negotiable line of defense these days, particularly for accounts that contain Personally Identifiable Information (PII) or other important data.<\/p>\n<p>The risks rise sharply in <a href=\"https:\/\/www.welivesecurity.com\/2023\/05\/04\/creating-strong-user-friendly-passwords-tips-business-password-policy\/\">corporate environments<\/a>. Weak, obvious, or reused passwords can expose not only individual employees, but <a href=\"https:\/\/www.welivesecurity.com\/en\/business-security\/cybercriminals-hacking-systems-logging-in\/\">entire organizations<\/a>, their customers, and their partners. Indeed, in many cases, the initial point of entry is neither sophisticated nor novel; instead, it\u2019s simply a password that should never have been trusted in the first place. The consequences, meanwhile, are rarely trivial and span financial loss, operational disruption, regulatory scrutiny, and long-term reputational damage. Which is why companies need a combination of technical safeguards and ongoing <a href=\"https:\/\/www.welivesecurity.com\/en\/business-security\/making-it-stick-get-most-cybersecurity-training\/\">security awareness training programs<\/a> for employees.<\/p>\n<p>Meanwhile, the technical barriers for ne\u2019er-do-wells have never been lower. Modern tools can test countless combinations of login credentials in minutes, so the odds are firmly stacked in the attacker\u2019s favor. Plus, in the digital ecosystem built on interconnected services and shared identities, the damage stemming from one account takeover is unlikely to stay contained for long.<\/p>\n<p>Also, <a href=\"https:\/\/www.welivesecurity.com\/2023\/06\/20\/passwords-out-passkeys-in-ready-make-switch\/\">passkeys<\/a> are rapidly becoming commonplace, and many major platforms, including Apple, Google, and Amazon, now offer them as a primary login method.<\/p>\n<p>You might have had many New Year\u2019s resolutions heading into 2026. But if your own passwords appear on either list above, improving your account security should be one of the most important of them.<\/p>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/old-habits-die-hard-2025-most-common-passwords\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Once again, data shows an uncomfortable truth: the habit of choosing eminently hackable passwords is alive and well<\/p>\n","protected":false},"author":5,"featured_media":8902,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-8901","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8901","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8901"}],"version-history":[{"count":1,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8901\/revisions"}],"predecessor-version":[{"id":9626,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8901\/revisions\/9626"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8902"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8901"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8901"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8901"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}