Disclaimer: We sustain our work & review products through paid collaborations.
The Worst of the Worst: The Most Common Passwords of 2017

The Worst of the Worst: The Most Common Passwords of 2017


Keeping several passwords for all those accounts you use every day is never an easy task, so it isn’t too surprising that still many people either rely on the very same password for each and every site or they turn to the most common and least secure solution, by using a ridiculously simple password that they can remember.

The most common passwords in 2017

However, hackers know that lots of people don’t bother creating strong passwords and the moment they acquire user data the very first thing they will do is to try out common weak passwords so they can break into as many accounts as possible. Although more and more users listen to security experts and the likes of handy solutions like password managers are getting more common with each passing day, the sad thing is that the most popular passwords can still be cracked with very little effort.

The common traits of common passwords

According to research conducted by Keeper Security based on the biggest data breaches of 2016, the trend of using bad passwords won’t change anytime soon and not just because a shocking one fifth of web surfers still use “123456” as a password. The problems uncovered by Keeper Security are more complex due to various factors: first and foremost, the list we’ve put together could’ve been written any time between 2010 and the present, meaning that the vast majority of internet users still don’t pay any attention to the warnings of security experts.

Another finding by Keeper is that most weak passwords usually consist of six characters or less, which can be easily decoded by brute-force cracking software. Passwords using unpredictable patterns but still having a strong resemblance to the worst passwords can still be cracked by hackers as dictionary-based password crackers are already programmed to look for sequential key variations.

Password strength

And last but not least here’s a little trivia that explains the seemingly random passwords on most of these worst of the worst lists: they are often created by bots setting up dummy accounts on public email services created for the sole purpose of spamming the internet – suggesting that service providers are equally responsible for the situation.

The top 10 most common passwords

And now without further ado it’s time to see what passwords were the most common (and the easiest to crack) in 2016 according to internet security firm SplashData:

  1. 123456
  2. password
  3. 12345
  4. 12345678
  5. football
  6. qwerty
  7. 1234567890
  8. 1234567
  9. princess
  10. 1234

As you can see the dominance of the two most common passwords, “123456” and “password”, is still unquestionable even in spite of the many public outcries by security experts. What’s more interesting is that most internet users still trust numeric passwords where the numbers are in an easily identifiable sequential order. Using characters appearing next to each other on the keyboard is also very popular, as well as words that are trending on the internet over a certain period of time. Although not appearing on our list, many people are safeguarding their accounts with random words from a dictionary, words that are profane or they just simply change a character (from “O” to “0”, for instance) but still leave the password otherwise completely recognizable.

How to avoid weak passwords

The first and most obvious way of securing your accounts is to never use any of the above mentioned passwords, neither as they appear nor with certain characters replaced with something else. The same rule applies to passwords that are randomly selected from a thesaurus, since the so-called dictionary attack – where the attacking software searches for words from the dictionary – will easily crack those too. And even if the password passes the big test – meaning it has ambiguous characters, upper and lower case letters, and numbers – you should only use it once, because if used on multiple sites and it is revealed then the rest of your accounts can be easily compromised.

Password strength

Therefore, the best way to protect yourself from data breaches is to use a new, long and complex password on every site you register with. Thankfully you don’t need to remember each of them. Browsers are capable of storing these passwords for you, but if you want the perfect protection then it’s best to turn to a password manager like Dashlane or 1Password where you only have to memorize one master password and the rest is taken care of for you.


Best password managers of 2025

Editors' choice

RoboForm

Editor's rating:
Identifies weak, reused passwords
Future-ready, seamless logins
Easy to use
Budget-friendly
Families

LastPass

Editor's rating:
Logical interface
Automated password categorization
Advanced mobile version
Various two-factor authentication options
Businesses

1Password

Editor's rating:
Keeps your data fully private
Protects against unauthorized access
Protects against unauthorized access
One-time password support
Security features

Keeper

Editor's rating:
Protects against data breaches
Works on all major devices
Budget-friendly
Help when you need it
Personal use

NordPass Personal

Editor's rating:
Keeps data safe and encrypted
Creates strong, unique passwords
Great value at no cost
Affordable premium upgrade
Password sharing

Dashlane

Editor's rating:
Updates weak passwords quickly
Encrypts your online traffic
Easy migration from other tools
Full mobile functionality
Local storage

Enpass

Editor's rating:
Comprehensive password management
No cost on desktops
Full control of your data
Keeps your info fully secure

Discussions

Share your thoughts, ask questions, and connect with other users. Your feedback helps our community make better decisions.

©2012-2025 Best Reviews, a clovio brand – All rights reserved