Most Popular Password Turns Out to Be 123456

If you wonder what happens to all of the data in a typical breach, you simply need to peer into the "dark web," the name given to that part of the internet not indexed by the popular search engines and requiring special tools to access. The dark web hosts multiple activities, many of which are perfectly legal and others that aren't, such as markets for buying drugs, guns and, yes, data pulled off computer systems through illegal means.

Recently, researchers at security firm 4iQ reported that they'd found a database of 1.4 billion clear text credentials, an aggregate database twice as large as any other ever uncovered in the dark web. It was discovered, according to an article posted to Medium by CEO Julio Casal, "in an underground community forum." Casal wrote that none of the passwords were encrypted; after testing a "subset," many were verified to be real and still active. The database aggregated the contents from 252 data breaches, including large ones (LinkedIn) and small ones (Bitcoin).

"This database makes finding passwords faster and easier than ever before," wrote Casal. "As an example, searching for 'admin,' 'administrator' and 'root' returned 226,631 passwords of admin users in a few seconds."

Casal included a list of the 40 most commonly used passwords, along with the count of how many times they were discovered in the database. Here are the top 10:

  • 123456, found 9.2 million times;
  • 123456789, found 3.1 million times;
  • qwerty, found 1.66 million times;
  • password, found 1.3 million times;
  • 111111, found 1.3 million times;
  • 12345678, found 1.1 million times;
  • abc123, found 1.1 million times;
  • 1234567, found 970,000 times;
  • password1, found 952,000 times; and
  • 1234567890, found 880,000 times.

Since the original article appeared, Casal's company has provided a link where users can enter their e-mail addresses and receive truncated versions of passwords included in the database tied to that account. If no exposed passwords were uncovered, 4iQ will also let them know that.

"This experience of searching and finding passwords within this database is as scary as it is shocking," Casal said. "Almost all of the users we've checked have verified the passwords we found were true."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • geometric pattern features abstract icons of a dollar sign, graduation cap, and document

    Maricopa Community Colleges Adopts Platform to Combat Student Application Fraud

    In an effort to secure its admissions and financial processes, Maricopa Community Colleges has partnered with A.M. Simpkins and Associates (AMSA) to implement the company's S.A.F.E (Student Application Fraudulent Examination) across the district's 10 institutions.

  • stylized figures, resumes, a graduation cap, and a laptop interconnected with geometric shapes

    OpenAI to Launch AI-Powered Jobs Platform

    OpenAI announced it will launch an AI-powered hiring platform by mid-2026, directly competing with LinkedIn and Indeed in the professional networking and recruitment space. The company announced the initiative alongside an expanded certification program designed to verify AI skills for job seekers.

  • Abstract AI circuit board pattern

    New Nonprofit to Work Toward Safer, Truthful AI

    Turing Award-winning AI researcher Yoshua Bengio has launched LawZero, a new nonprofit aimed at developing AI systems that prioritize safety and truthfulness over autonomy.

  • hooded figure types on a laptop, with abstract manifesto-like posters taped to the wall behind them

    Hacktivism Is a Growing Threat to Higher Education

    In recent years, colleges and universities have faced an evolving array of cybersecurity challenges. But one threat is showing signs of becoming both more frequent and more politically charged: hacktivism.