Most Popular Password Turns Out to Be 123456

If you wonder what happens to all of the data in a typical breach, you simply need to peer into the "dark web," the name given to that part of the internet not indexed by the popular search engines and requiring special tools to access. The dark web hosts multiple activities, many of which are perfectly legal and others that aren't, such as markets for buying drugs, guns and, yes, data pulled off computer systems through illegal means.

Recently, researchers at security firm 4iQ reported that they'd found a database of 1.4 billion clear text credentials, an aggregate database twice as large as any other ever uncovered in the dark web. It was discovered, according to an article posted to Medium by CEO Julio Casal, "in an underground community forum." Casal wrote that none of the passwords were encrypted; after testing a "subset," many were verified to be real and still active. The database aggregated the contents from 252 data breaches, including large ones (LinkedIn) and small ones (Bitcoin).

"This database makes finding passwords faster and easier than ever before," wrote Casal. "As an example, searching for 'admin,' 'administrator' and 'root' returned 226,631 passwords of admin users in a few seconds."

Casal included a list of the 40 most commonly used passwords, along with the count of how many times they were discovered in the database. Here are the top 10:

  • 123456, found 9.2 million times;
  • 123456789, found 3.1 million times;
  • qwerty, found 1.66 million times;
  • password, found 1.3 million times;
  • 111111, found 1.3 million times;
  • 12345678, found 1.1 million times;
  • abc123, found 1.1 million times;
  • 1234567, found 970,000 times;
  • password1, found 952,000 times; and
  • 1234567890, found 880,000 times.

Since the original article appeared, Casal's company has provided a link where users can enter their e-mail addresses and receive truncated versions of passwords included in the database tied to that account. If no exposed passwords were uncovered, 4iQ will also let them know that.

"This experience of searching and finding passwords within this database is as scary as it is shocking," Casal said. "Almost all of the users we've checked have verified the passwords we found were true."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  •  floating digital interface with glowing icons, surrounded by faint geometric shapes

    Digital Education Council Defines 5 Dimensions of AI Literacy

    A recent report from the Digital Education Council, a global community devoted to "revolutionizing the world of education and work through technology and collaboration," provides an AI literacy framework to help higher education institutions equip their constituents with foundational AI competencies.

  • From Fire TV to Signage Stick: University of Utah's Digital Signage Evolution

    Jake Sorensen, who oversees sponsorship and advertising and Student Media in Auxiliary Business Development at the University of Utah, has navigated the digital signage landscape for nearly 15 years. He was managing hundreds of devices on campus that were incompatible with digital signage requirements and needed a solution that was reliable and lowered labor costs. The Amazon Signage Stick, specifically engineered for digital signage applications, gave him the stability and design functionality the University of Utah needed, along with the assurance of long-term support.

  • lock with a glowing keyhole integrated with a transparent, layered server stack against a dark background with a subtle grid pattern

    Cohesity Integration Adds Protection for Red Hat OpenShift Virtualization Workloads

    AI-powered data security company Cohesity has expanded its collaboration with Red Hat to enhance data protection and cyber resilience for Red Hat OpenShift Virtualization workloads.

  • computer screen displaying a landline phone being unplugged from a single cord, with a modern office desk, keyboard, and subtle lighting in the background

    Microsoft to Discontinue Skype Services

    Microsoft has announced that it is shutting down service for its Skype telecommunications and video calling services on May 5, 2025.