Bad Passwords 2022

Bad Passwords 2022Password manager proprietor NordPass has released it’s third annual list of most common passwords. The firm worked with security experts to cull the top compromised passwords for 2022 from 3TB of stolen password data found on the dark web. What they found is like déjà vu, all over again. 

NordPass2022’s most commonly found password “password” has been in the top 5 since 2019. “Password” was found nearly 5 million times in the NordPass list from the dark web. Eight variants of “password” are included in the list.

RankPasswordCount
1password4,929,113
34pass@1233,9046
56password125,113
139Password12,029
173password1239,889
188Pass@1239,359
189passw0rd9,349
192Password19,220

The second most popular password “123456” had held the number 1 spot in 2020 and 2021.

C-level passwords

NordPass also looked at leaked C-level passwords. The big bosses are not better than their staff. C-level staff use the same top ten bad passwords.

  1. 123456
  2. password
  3. 12345
  4. 123456789
  5. qwerty
  6. 1234
  7. qwerty123
  8. 1q2w3e
  9. 111111
  10. 12345678

Other password facts

For the first time the Nordpass results were broken out by gender. Both men and women favored the same top bad passwords.

Password

Movies on the list:

#125 “superman” was used 12,100 times.

#171 “matrix” was used 10,122  times.

#185 “batman” was used 9,407 times.

#196 “starwars”  was used 9,091 times.

Hockey teams are popular for bad passwords. “Detroit Red Wings” and “Columbus Blue Jackets” were among the most popular sports themed bad passwords.

On the music front, “U2”, “Prince” and “Metallica” were popular hacked passwords.

Small cars are popular for lazy passwords. “mini”, “kia”, and “vw” were frequently used.

2022’s worst passwords

RankPasswordChange
from 2021
1password+4
2123456+1
3123456789-1
4guestNew
5qwerty-1
6123456780
71111110
812345-5
9col123456New
10123123-2
111234567-1
121234+5
131234567890-4
14000000-2
15555555New
16666666+8
17123321+2
18654321+5
197777777New
20123New
21d1lakissNew
2277777New
23110110jpNew
241111New
259876543210

rb-

It is worth pointing out again, and again again.

  1. how can you keep your online personal information safe?Make sure none of your passwords are on this (or any other list). If they are log on and change them immediately.
  2. Use two-factor authentication, whenever possible. Even if a hacker has your password, they won’t have that random code and therefore won’t be able to get into your account. Not sure if your favorite website supports two-factor authentication, search the Two Factor Auth List to find out.
  3. Consider a password manager. Your brain is no longer an adequate password manager.

How you can help Ukraine!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Comments are closed.