Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

123456 is still the world’s most common password, according to NordPass’s 2025 report. That does not mean every weak password appears on a published list. Short sequences, names, dates, keyboard patterns, reused credentials and predictable substitutions are all easy targets.

The practical fix is straightforward: use a unique password for every account, make manually created passwords at least 15 characters long, store credentials in a reputable password manager, and enable MFA or a passkey wherever available.

What are the most common passwords right now?

The latest widely cited annual dataset located for this topic is NordPass’s 2025 Top 200 Most Common Passwords report. It analyzed exposed credentials from public data breaches and dark-web repositories collected between September 2024 and September 2025, covering password trends in 44 countries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NordPass reports that 123456 remained the global leader and has topped its chart in six of the seven years covered by the company’s series. Because the report uses exposed credentials rather than a census of every password in use, its rankings should be treated as evidence of recurring patterns—not as a universal list of everyone’s passwords.

#1 Best Overall
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

The report includes global, country-specific and generational tables. Exact rankings can differ according to geography, language, age group, source data and deduplication methods, so the most useful lesson is the pattern behind the rankings:

Weak-password pattern Representative examples Why it fails
Numeric sequences 123456, 12345, 123456789 They are among the first combinations tested by automated guessing tools.
Common words and defaults password, admin, welcome They appear in dictionaries, default-credential lists and breach databases.
Keyboard paths qwerty, qwerty123, asdfgh Their construction is obvious and widely modeled.
Names and numbers maria123, john2025 Names, years and other personal details are easy to guess or obtain.
Predictable substitutions P@ssw0rd, Password1! Replacing letters or adding a capital, number and symbol is already included in cracking dictionaries.
Popular culture Sports teams, brands, games, films, memes and celebrities Popular terms are common inputs for targeted guessing.
Local-language words Translated versions of “password” and other familiar words Attackers use multilingual and regional wordlists.

Do not copy these examples as a test of whether your password is “on the list.” If a password follows one of these patterns, replace it even if the exact combination is not publicly ranked.

Common does not always mean identical to weak

Common means a password appears frequently in an exposed-credential dataset. Weak means it is easy to guess, derive, crack, reuse or compromise in the relevant attack scenario.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A password can be absent from a public top-200 list and still be weak if it is:

  • short;
  • based on your name, pet, school, employer, team or birthday;
  • a famous quotation, lyric, slogan or common phrase;
  • used on another website;
  • an old password with the current year appended; or
  • a predictable variation such as Password2! after using Password1!.

Conversely, a long, randomly generated password may not appear in any list and is substantially harder to guess—provided it is unique and stored safely.

How common-password lists are made—and their limits

Researchers generally assemble these rankings from password collections exposed in data breaches, leaks and other repositories. NordPass says its 2025 study used aggregated data from public breaches and dark-web repositories and that it did not purchase personal data for the research.

Such lists have important limitations:

  • They show passwords that have been exposed, not every password currently in use.
  • The source collections may contain duplicates, corrupted records, automated accounts, defaults or compromised systems.
  • Rankings depend on which countries, languages, services and breaches are included.
  • Different researchers may deduplicate and classify entries differently.
  • A vendor’s list cannot be treated as a universal census or a safety checklist.

NordPass also sells a password manager, so its research claims and product promotion should be considered separately. The report remains useful for identifying broad habits, but the exact rank of a password is less important than whether its construction is predictable or reused.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Atlancube PasswordPocket Offline Hardware Password Keeper with Bluetooth Auto-Fill for iPhone and Android, Stores 1,000 Logins, Military-Grade AES-256 Encryption (Black)
  • Auto-Fill Feature: Say goodbye to the hassle of manually entering passwords! PasswordPocket automatically fills in your credentials with just a single click.
  • Internet-Free Data Protection: Use Bluetooth as the communication medium with your device. Eliminating the need to access the internet and reducing the risk of unauthorized access.
  • Military-Grade Encryption: Utilizes advanced encryption techniques to safeguard your sensitive information, providing you with enhanced privacy and security.
  • Offline Account Management: Store up to 1,000 sets of account credentials in PasswordPocket.
  • Support for Multiple Platforms: PasswordPocket works seamlessly across multiple platforms, including iOS and Android mobile phones and tablets.

Why these passwords are so easy to attack

Dictionary guessing

Attackers do not start with every possible random character combination. They begin with common words, names, leaked passwords, keyboard patterns, dates and popular terms. Modern dictionaries also include predictable changes such as capitalizing the first letter, adding a year or replacing letters with symbols.

The National Institute of Standards and Technology (NIST) specifically warns that dictionary words, previously breached passwords and variants such as Password1! are poor choices.

Password spraying

Password spraying tries a small number of widely used passwords against many accounts instead of repeatedly attacking one account. This is why a password can be dangerous even when an individual user’s name is unknown.

Credential stuffing

When a website’s credential database is exposed, criminals may test the same username-and-password combinations on other services. Reuse turns one compromised account into a possible route into email, banking, shopping, work and social-media accounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST describes reuse as a major weakness. A password that is strong in isolation is not strong in practice if it protects several accounts.

Personal-information guessing

Names, children’s names, pets, employers, schools, sports teams, locations and dates often appear on social media or in public records. Combining one with a predictable number does not provide meaningful protection.

Offline attacks

If attackers steal password hashes, they may test guesses without the login page’s normal rate limits. The exact risk depends on the service’s password-hashing method, the attacker’s resources and the password distribution, so generic “crack time” calculators should not be treated as guarantees.

Rank #3
Sale
Elegant Password Book with Alphabetical Tabs - Hardcover Password Book for Internet Website Address Login - 5.2" x 7.6" Password Keeper and Organizer w/Notes Section & Back Pocket (Turquoise)
  • NEVER FORGET A PASSWORD AGAIN: Almost every App. has a password, it is almost impossible to remember all the password log in details. This password book is specifically designed to help you create secure passwords and store all your passwords safely in one place. You will never forget your password log-in details again with this password keeper.
  • ALPHABETICAL A-Z TABS FOR QUICK ACCESS: Alphabetical tabs design allows you to store your passwords alphabetically so you can find what you want faster, no more annoying searches!
  • ANONYMOUS WITHOUT ANY TITLE: On the outside, this password notebook organizer looks just like those writing journals, there is no title listed on the cover, so no one would know it's a password book. But we still recommend keeping the internet password logbook in a safe place such as a locked drawer or a shelf full of books.
  • THICK NO-BLEED PAPER: This 5.2" x 7.6" password book contains 74 sheets of thick 120gsm paper that resists ink smearing, say goodbye to those cheap password books that bleed ink!
  • PREMIUM QUALITY & PERFECT MEDIUM SIZE: This password journal comes with a high-quality leatherette hardcover, an elastic band, pen holder, ribbon bookmarker, and inner accordion pocket. It measures 5.2 inches wide and 7.6 inches long, which is the perfect size for your needs.

Phishing and malware

A strong password can still be surrendered to a fake login page or captured by malware such as a keylogger. Passkeys and phishing-resistant MFA address risks that password length alone cannot solve.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What makes a password strong?

Judge a password using more than a website’s strength meter:

  1. Unique: It is used nowhere else.
  2. Long: If you create it manually, NIST consumer guidance recommends at least 15 characters.
  3. Unpredictable: Its construction is not based on a familiar word, personal detail or obvious pattern.
  4. Unexposed: It has not appeared in a breach or known-password blocklist.
  5. Safely stored: You can retrieve it without reusing or writing it in an unprotected place.
  6. Protected by another factor: MFA or a passkey is enabled where supported.

For most accounts, the best choice is a password-manager-generated random password. If you must create one yourself, use a long passphrase made from multiple unrelated words. A phrase is not automatically strong if it is a famous quotation, song lyric, slogan or common expression.

Length matters more than superficially complicated rules. A short password containing one uppercase letter, one number and one symbol may be easier to predict than a longer, less artificial phrase. NIST does not recommend mandatory composition rules as the primary control, although individual websites may still require particular characters.

How to fix weak passwords: a practical order of operations

  1. Secure your email and primary identity accounts first. These accounts can often reset other passwords. Use a unique credential and MFA or a passkey.
  2. Stop reuse. Change any password shared between services, especially the password for your email account.
  3. Act on breach alerts. Change credentials immediately if a service reports exposure or you suspect compromise.
  4. Generate a different credential for every important account. Do not make variations of one master password.
  5. Enable MFA. Prefer passkeys, hardware security keys or authenticator apps over SMS when the stronger options are available.
  6. Add passkeys. They can reduce dependence on passwords on participating websites and devices.
  7. Store recovery codes securely. Keep them somewhere you can access when your usual device is unavailable.
  8. Review your password manager. Protect its account with MFA, update its apps and plan how you will recover access or provide emergency access if needed.

Password managers and passkeys solve different problems

Password managers

A password manager generates, stores and autofills unique credentials, reducing reuse and the need to memorize dozens of passwords. Many can flag weak, reused or exposed credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A manager is not unhackable. It concentrates valuable information in a vault, so the account protecting that vault needs a strong master credential, MFA and carefully stored recovery information. Keep the app updated and be cautious when autofill appears on an unfamiliar domain.

You do not have to pay for a password manager. Reputable free options such as Bitwarden Free and Proton Pass Free can address the central need: generating and storing unique credentials. Paid plans may add sharing, monitoring, aliases, attachments, family administration or broader ecosystem features. Choose based on features and trust, not on the assumption that a subscription is required.

Rank #4
Sale
Clever Fox Password Book with Alphabetical Tabs, 4"x5.5" Keeper Black
  • NEVER FORGET A PASSWORD AGAIN - Clever Fox password journal will help you create secure passwords and keep them safe and organized. This password book allows you to store all your passwords and other computer information in one place to find it easily.
  • ALPHABETICAL A-Z TABS - Alphabetic tab system makes it easy to find any password you need. The book also has sections for most important passwords, wireless & email settings, software license information & additional notes.
  • ELEGANT, SMART, PRACTICAL & SECURE PASSWORD ORGANIZATION - This password keeper book has been designed to be anonymous without an obvious title on the cover. For added security there is space to write hints instead of the password itself.
  • POCKET SIZE & PREMIUM QUALITY - This internet address and password logbook with tabs comes in pocket size (4.0x5.5 inches). The password notebook has an eco-leahter hardcover, elastic band, pen loop, bookmark, pocket for notes, and thick 120gsm paper.
  • 60-DAY MONEY-BACK GUARANTEE - We will exchange or refund your password organizer if you aren’t satisfied with your password organization for any reason. Reach out to us via message to refund your internet password logbook.

Passkeys

Passkeys are designed to replace shared passwords on supported services. They use public-key cryptography and are generally resistant to traditional credential phishing and password reuse when implemented correctly.

They are not available everywhere. Support depends on the website, device, browser and account-recovery process. You still need to protect your email and identity-provider accounts, maintain recovery methods for lost devices and secure the devices that hold your passkeys. For many people, the practical answer is to use both: passkeys where supported and a password manager for accounts that still require passwords.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Important edge cases

Banking and healthcare websites

Some services still impose outdated length or character restrictions. Use the strongest unique credential the service accepts, then enable every strong MFA option it provides. Do not weaken the password on other accounts to match the restrictive site.

Wi-Fi passwords

Replace the router’s default password. A long passphrase is usually easier to share with household members than a short, complex-looking string. Also change the router’s administrator password if it is separate from the Wi-Fi password.

Shared family accounts

Use a family password manager or the service’s delegated-access feature rather than sending credentials through chat or keeping them in an unencrypted notes file.

Work accounts

Follow your organization’s policy and use its approved password manager, single sign-on system or security key. Do not move company credentials into a personal vault without permission.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security questions

Treat security-question answers as additional passwords. If a service requires them, use random answers and save them in the password manager rather than choosing information that can be found online.

Best Value
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
  • Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More
  • Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
  • Enter one PIN number and have access to 400 accounts. Search function included.
  • Unit auto locks for 30 minutes after 5 consecutive incorrect PIN attempts
  • Includes mini stylus for easier keypad entry

Password-protected files

A password manager does not protect a file after the file has been copied elsewhere or the device is compromised. Use the file format’s current encryption features and protect the device itself.

Should you change passwords regularly?

Do not change every password on an arbitrary monthly or quarterly schedule just because a calendar reminder says so. Forced rotation often produces predictable changes such as adding a new number or year.

Change a password immediately when it is exposed, reused, shared improperly, suspected to be compromised, or covered by a breach notification. Replace weak passwords during a security review and upgrade accounts to MFA or passkeys when possible. NIST’s current guidance emphasizes length, blocklists of known-compromised passwords, password managers and MFA rather than routine expiration for its own sake.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Final password-security checklist

  • Use a unique password for every account.
  • Create manually chosen passwords of at least 15 characters.
  • Prefer random generation from a reputable password manager.
  • Avoid sequences, names, dates, keyboard paths, famous phrases and predictable substitutions.
  • Secure email, identity-provider and password-manager accounts first.
  • Enable MFA, preferring passkeys, security keys or authenticator apps where available.
  • Use passkeys on supported services.
  • Store recovery codes and emergency-access information securely.
  • Respond immediately to breach alerts.
  • Never assume a password is safe simply because it is absent from one published list.

Frequently Asked Questions

Is Password1! safe?

No. It combines a common word with the predictable capital letter, number and symbol pattern specifically warned about by NIST. Replace it with a unique, long credential generated by a password manager.

Is a 20-character password always safe?

No. Length helps, but a 20-character password can still be weak if it is reused, based on a famous phrase, exposed in a breach or entered into a phishing site.

What should I do after a data breach?

Change the affected password immediately, change it anywhere else it was reused, secure the associated email account, enable MFA and review active sessions and recovery methods.

Should I save passwords in my browser?

A reputable browser password manager can be safer than reuse or unencrypted notes. Keep the browser and device updated, protect the account with MFA and avoid autofill on suspicious domains.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What if I forget my password-manager master password?

Use the manager’s documented recovery options, emergency access or stored recovery information. Do not create a second vault and abandon the first until you understand whether its data can be recovered.

Quick Recap

SaleBestseller No. 1
Password Safe
Password Safe
Requires 3 "AAA" batteries (included); Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
$30.80
Bestseller No. 5
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More; Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
$37.84

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.