The hardest passwords to hack are long, random strings of characters that use a combination of uppercase letters, lowercase letters, numbers, and symbols. Passphrases, which consist of several unrelated words, are also an effective and memorable option.
– that 8675309 is the fourth most commonly used 7-digit password. (If you're wondering the “no surpise” most popular 7-digit password is 1234567.)
A Password is a word, phrase, or string of characters intended to differentiate an authorized user or process, for the purpose of permitting access (such as via logging in) from an unauthorized user. Defined another way, a password is used to prove one's identity, or authorize access to a resource.
Simple passwords, such as 12345, or common identifying information, like birthdays and pet names, are not safe for protecting important accounts holding personal information. Using an easy-to-guess password is like locking the door but leaving the key in the lock.
Three random words generate a password that is not only long enough to thwart brute force attacks but also complex enough to resist common guessing techniques.
Many of the stolen passwords were embarrassingly simple. Variations of “password123,” “123456,” and “linkedin” (creative, right?) were found everywhere. This breach wasn't just an inconvenience—it was a gateway for hackers to access other accounts, since many users reused the same password across multiple platforms.
Human brains were responsible for choosing passwords like "123456", "password," and "qwerty." But there is no way that 91,103 people independently chose to secure their accounts with "18atcskd2w." Instead, what I believe happened is that these accounts were created by bots, perhaps with the intention of posting spam ...
Make sure you use at least 12 characters. Use a combo of uppercase letters, lowercase letters, numbers, and even some special characters (!, @, $, %, ^, &, *, +, #) in ALL passwords.
Chance of being hacked is 1 in 5
On average, a customer is hacked 0.3 times. Due to some companies being affected by hacking more than once, the chances of your business being affected by a cyber incident come out to a shocking 1 in 5.
The "8 4 Rule" for strong passwords is a guideline requiring a minimum length of 8 characters (the "8") and the inclusion of 4 different character types (the "4"): at least one lowercase letter, one uppercase letter, one number, and one special symbol, creating a complex, hard-to-guess password. While once a standard, modern advice often emphasizes length and passphrase-style passwords over strict complexity rules for better usability, though the principles of mixed character types remain important.
The Least Common PINs
According to the same data, the least commonly used 4-digit PIN is 8068, with just 25 occurrences out of the 3.4 million passwords examined — a minuscule 0.000744% frequency . The 10 least popular 4-digit PINs found in the study's dataset, starting with the least common, are: 8068. 8093.
Because our normal number base is 10, so that is all we need. These symbols, known as “Arabic numerals” were adopted from India and the Middle East to replace the Roman numeral system, IVXLCDM, which was non-positional, lacked zero, and had only 7 numeral symbols borrowed from the alphabet.
This year's winner, 123456, has come top three times. It has only been beaten by 12345, which happened in 2019, and by the ever-popular “password”, in 2022. Here are the 200 most common passwords from 2019-2022.
Most hackable passwords
Second came “123456” followed by the slightly longer “123456789.” Rounding out the top five were “guest” and “qwerty.” Most of those log-ins can be cracked in less than a second.
The term 'pwned” comes from video game slang and is a leetspeak variant of the word 'owned'. It originated from a typing mistake (typing 'p' instead of 'o') and came to signify that someone has been defeated. In security terms, if your account was 'pwned', it means it was involved in a data breach.
More than 90% of successful cyber-attacks start with a phishing email.
If you see yours here, it's time for an immediate change!
If you use one of these PINs, change it immediately they're easy to guess and have been exposed in data breaches: 1234, 1212, 1122, 1010, 1342, 4321, 1111, 2222, 3333, 4444, 5555, 6666, 7777, 8888, 9999, 0000, 1984, 1986, 1989, 2010, 2020.
They also prefer numbers that are easy to type, like the figure “2580” which goes straight down the numberpad. Other predictable numbers stem from the fact that we use birthdays and birth-years so we can easily remember the PIN code.
A strong password is: At least 12 characters long but 14 or more is better. A combination of uppercase letters, lowercase letters, numbers, and symbols. Not a word that can be found in a dictionary or the name of a person, character, product, or organization.
Make it random
The password has a combination of uppercase and lowercase letters, numbers, special characters, and words with no discernable pattern, unrelated to your personal information.
Most sites will have a 'Forgot Password' option available for this very sake. Click this button and follow the steps to reset your password. If it's a non-email password (like Facebook), resetting a password will be fairly easy.