Password security guide

TOP 10 Worst Passwords

Some passwords are so predictable that attackers do not need sophisticated hacking tools to guess them. They are already near the front of the queue. Here are the ten most common passwords in the latest global NordPass list, based on data from public breaches and dark-web repositories collected from September 2024 to September 2025.

If your password looks like a number sequence, a default account name, or a very obvious variation such as admin123, assume attackers have already tried it. Use a unique password generated by a password manager instead.

The 10 passwords you really don't want to use

  1. 1123456The perennial favourite
  2. 2adminA default-style credential
  3. 312345678Simple number sequence
  4. 4123456789Longer, but still predictable
  5. 512345Five guesses' worth of effort
  6. 6passwordLiterally says what it is
  7. 7Aa123456Looks complex; follows a known pattern
  8. 81234567890The whole number row
  9. 9Pass@123A predictable “complex” variation
  10. 10admin123Default name + numbers
One interesting detail
123456

NordPass says 123456 has been the world's most common password for six of the last seven years. Adding a few characters to an obvious pattern does not magically make it safe.

Why are these passwords so bad?

The problem is not simply that they are short. It is that they are predictable. Attackers do not necessarily start by trying every possible combination. Automated password attacks commonly begin with dictionaries, lists of known passwords, leaked credentials and variations of passwords people repeatedly choose.

That is why passwords such as admin123 and Pass@123 are still poor choices. They look more complicated than 123456, but the underlying pattern is extremely familiar.

Don't make a “better” version of a bad password

A surprisingly common idea is to take a familiar password and decorate it:

These changes may satisfy a website's character rules, but they can still be predictable. OWASP specifically notes that attackers use password lists and variations of previously exposed credentials in automated attacks.

What should you use instead?

The easiest answer for most people is: don't invent passwords yourself. Let a reputable password manager generate a different random password for every account.

  1. Click on Generate a Strong Password
  2. Generate a strong, unique password when creating or changing an account
  3. Store the generated password in the safe place (usb flashdrive, password manager, etc)
  4. Never reuse the same password for important accounts
Remember: The goal is not to create a password that is clever enough for you to remember. The goal is to create a credential that an attacker cannot predict.

Already using one of these?

Change it. Start with your email account, banking, shopping, social-media and other accounts containing personal or financial information. If you have reused the same password elsewhere, change those accounts too.

A password manager makes this much easier because you no longer have to remember dozens of new passwords.


Quick password safety checklist

Every important account has a unique password.
No password appears on a common-password list.
You are not simply adding numbers to an old password.
Compromised passwords have been replaced.
Two-factor authentication is enabled where available.
A password manager generates and stores your passwords.

Bottom line

There is nothing wrong with using a password that is easy for you to remember — until that same password is also easy for an attacker to guess. 123456, admin, password and their close relatives are not secret anymore. Let your password manager handle the hard part and reserve your memory for things that actually matter.