Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
123456 is still the world’s most common password, according to NordPass’s 2025 report. That does not mean every weak password appears on a published list. Short sequences, names, dates, keyboard patterns, reused credentials and predictable substitutions are all easy targets.
The practical fix is straightforward: use a unique password for every account, make manually created passwords at least 15 characters long, store credentials in a reputable password manager, and enable MFA or a passkey wherever available.
What are the most common passwords right now?
The latest widely cited annual dataset located for this topic is NordPass’s 2025 Top 200 Most Common Passwords report. It analyzed exposed credentials from public data breaches and dark-web repositories collected between September 2024 and September 2025, covering password trends in 44 countries.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchNordPass reports that 123456 remained the global leader and has topped its chart in six of the seven years covered by the company’s series. Because the report uses exposed credentials rather than a census of every password in use, its rankings should be treated as evidence of recurring patterns—not as a universal list of everyone’s passwords.
#1 Best Overall
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
The report includes global, country-specific and generational tables. Exact rankings can differ according to geography, language, age group, source data and deduplication methods, so the most useful lesson is the pattern behind the rankings:
| Weak-password pattern | Representative examples | Why it fails |
|---|---|---|
| Numeric sequences | 123456, 12345, 123456789 |
They are among the first combinations tested by automated guessing tools. |
| Common words and defaults | password, admin, welcome |
They appear in dictionaries, default-credential lists and breach databases. |
| Keyboard paths | qwerty, qwerty123, asdfgh |
Their construction is obvious and widely modeled. |
| Names and numbers | maria123, john2025 |
Names, years and other personal details are easy to guess or obtain. |
| Predictable substitutions | P@ssw0rd, Password1! |
Replacing letters or adding a capital, number and symbol is already included in cracking dictionaries. |
| Popular culture | Sports teams, brands, games, films, memes and celebrities | Popular terms are common inputs for targeted guessing. |
| Local-language words | Translated versions of “password” and other familiar words | Attackers use multilingual and regional wordlists. |
Do not copy these examples as a test of whether your password is “on the list.” If a password follows one of these patterns, replace it even if the exact combination is not publicly ranked.
Common does not always mean identical to weak
Common means a password appears frequently in an exposed-credential dataset. Weak means it is easy to guess, derive, crack, reuse or compromise in the relevant attack scenario.
A password can be absent from a public top-200 list and still be weak if it is:
- short;
- based on your name, pet, school, employer, team or birthday;
- a famous quotation, lyric, slogan or common phrase;
- used on another website;
- an old password with the current year appended; or
- a predictable variation such as
Password2!after usingPassword1!.
Conversely, a long, randomly generated password may not appear in any list and is substantially harder to guess—provided it is unique and stored safely.
How common-password lists are made—and their limits
Researchers generally assemble these rankings from password collections exposed in data breaches, leaks and other repositories. NordPass says its 2025 study used aggregated data from public breaches and dark-web repositories and that it did not purchase personal data for the research.
Such lists have important limitations:
- They show passwords that have been exposed, not every password currently in use.
- The source collections may contain duplicates, corrupted records, automated accounts, defaults or compromised systems.
- Rankings depend on which countries, languages, services and breaches are included.
- Different researchers may deduplicate and classify entries differently.
- A vendor’s list cannot be treated as a universal census or a safety checklist.
NordPass also sells a password manager, so its research claims and product promotion should be considered separately. The report remains useful for identifying broad habits, but the exact rank of a password is less important than whether its construction is predictable or reused.
Rank #2
- Auto-Fill Feature: Say goodbye to the hassle of manually entering passwords! PasswordPocket automatically fills in your credentials with just a single click.
- Internet-Free Data Protection: Use Bluetooth as the communication medium with your device. Eliminating the need to access the internet and reducing the risk of unauthorized access.
- Military-Grade Encryption: Utilizes advanced encryption techniques to safeguard your sensitive information, providing you with enhanced privacy and security.
- Offline Account Management: Store up to 1,000 sets of account credentials in PasswordPocket.
- Support for Multiple Platforms: PasswordPocket works seamlessly across multiple platforms, including iOS and Android mobile phones and tablets.
Why these passwords are so easy to attack
Dictionary guessing
Attackers do not start with every possible random character combination. They begin with common words, names, leaked passwords, keyboard patterns, dates and popular terms. Modern dictionaries also include predictable changes such as capitalizing the first letter, adding a year or replacing letters with symbols.
The National Institute of Standards and Technology (NIST) specifically warns that dictionary words, previously breached passwords and variants such as Password1! are poor choices.
Password spraying
Password spraying tries a small number of widely used passwords against many accounts instead of repeatedly attacking one account. This is why a password can be dangerous even when an individual user’s name is unknown.
Credential stuffing
When a website’s credential database is exposed, criminals may test the same username-and-password combinations on other services. Reuse turns one compromised account into a possible route into email, banking, shopping, work and social-media accounts.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsNIST describes reuse as a major weakness. A password that is strong in isolation is not strong in practice if it protects several accounts.
Personal-information guessing
Names, children’s names, pets, employers, schools, sports teams, locations and dates often appear on social media or in public records. Combining one with a predictable number does not provide meaningful protection.
Offline attacks
If attackers steal password hashes, they may test guesses without the login page’s normal rate limits. The exact risk depends on the service’s password-hashing method, the attacker’s resources and the password distribution, so generic “crack time” calculators should not be treated as guarantees.
Rank #3
- NEVER FORGET A PASSWORD AGAIN: Almost every App. has a password, it is almost impossible to remember all the password log in details. This password book is specifically designed to help you create secure passwords and store all your passwords safely in one place. You will never forget your password log-in details again with this password keeper.
- ALPHABETICAL A-Z TABS FOR QUICK ACCESS: Alphabetical tabs design allows you to store your passwords alphabetically so you can find what you want faster, no more annoying searches!
- ANONYMOUS WITHOUT ANY TITLE: On the outside, this password notebook organizer looks just like those writing journals, there is no title listed on the cover, so no one would know it's a password book. But we still recommend keeping the internet password logbook in a safe place such as a locked drawer or a shelf full of books.
- THICK NO-BLEED PAPER: This 5.2" x 7.6" password book contains 74 sheets of thick 120gsm paper that resists ink smearing, say goodbye to those cheap password books that bleed ink!
- PREMIUM QUALITY & PERFECT MEDIUM SIZE: This password journal comes with a high-quality leatherette hardcover, an elastic band, pen holder, ribbon bookmarker, and inner accordion pocket. It measures 5.2 inches wide and 7.6 inches long, which is the perfect size for your needs.
Phishing and malware
A strong password can still be surrendered to a fake login page or captured by malware such as a keylogger. Passkeys and phishing-resistant MFA address risks that password length alone cannot solve.
Recommended Free Tools
What makes a password strong?
Judge a password using more than a website’s strength meter:
- Unique: It is used nowhere else.
- Long: If you create it manually, NIST consumer guidance recommends at least 15 characters.
- Unpredictable: Its construction is not based on a familiar word, personal detail or obvious pattern.
- Unexposed: It has not appeared in a breach or known-password blocklist.
- Safely stored: You can retrieve it without reusing or writing it in an unprotected place.
- Protected by another factor: MFA or a passkey is enabled where supported.
For most accounts, the best choice is a password-manager-generated random password. If you must create one yourself, use a long passphrase made from multiple unrelated words. A phrase is not automatically strong if it is a famous quotation, song lyric, slogan or common expression.
Length matters more than superficially complicated rules. A short password containing one uppercase letter, one number and one symbol may be easier to predict than a longer, less artificial phrase. NIST does not recommend mandatory composition rules as the primary control, although individual websites may still require particular characters.
How to fix weak passwords: a practical order of operations
- Secure your email and primary identity accounts first. These accounts can often reset other passwords. Use a unique credential and MFA or a passkey.
- Stop reuse. Change any password shared between services, especially the password for your email account.
- Act on breach alerts. Change credentials immediately if a service reports exposure or you suspect compromise.
- Generate a different credential for every important account. Do not make variations of one master password.
- Enable MFA. Prefer passkeys, hardware security keys or authenticator apps over SMS when the stronger options are available.
- Add passkeys. They can reduce dependence on passwords on participating websites and devices.
- Store recovery codes securely. Keep them somewhere you can access when your usual device is unavailable.
- Review your password manager. Protect its account with MFA, update its apps and plan how you will recover access or provide emergency access if needed.
Password managers and passkeys solve different problems
Password managers
A password manager generates, stores and autofills unique credentials, reducing reuse and the need to memorize dozens of passwords. Many can flag weak, reused or exposed credentials.
A manager is not unhackable. It concentrates valuable information in a vault, so the account protecting that vault needs a strong master credential, MFA and carefully stored recovery information. Keep the app updated and be cautious when autofill appears on an unfamiliar domain.
You do not have to pay for a password manager. Reputable free options such as Bitwarden Free and Proton Pass Free can address the central need: generating and storing unique credentials. Paid plans may add sharing, monitoring, aliases, attachments, family administration or broader ecosystem features. Choose based on features and trust, not on the assumption that a subscription is required.
Rank #4
- NEVER FORGET A PASSWORD AGAIN - Clever Fox password journal will help you create secure passwords and keep them safe and organized. This password book allows you to store all your passwords and other computer information in one place to find it easily.
- ALPHABETICAL A-Z TABS - Alphabetic tab system makes it easy to find any password you need. The book also has sections for most important passwords, wireless & email settings, software license information & additional notes.
- ELEGANT, SMART, PRACTICAL & SECURE PASSWORD ORGANIZATION - This password keeper book has been designed to be anonymous without an obvious title on the cover. For added security there is space to write hints instead of the password itself.
- POCKET SIZE & PREMIUM QUALITY - This internet address and password logbook with tabs comes in pocket size (4.0x5.5 inches). The password notebook has an eco-leahter hardcover, elastic band, pen loop, bookmark, pocket for notes, and thick 120gsm paper.
- 60-DAY MONEY-BACK GUARANTEE - We will exchange or refund your password organizer if you aren’t satisfied with your password organization for any reason. Reach out to us via message to refund your internet password logbook.
Passkeys
Passkeys are designed to replace shared passwords on supported services. They use public-key cryptography and are generally resistant to traditional credential phishing and password reuse when implemented correctly.
They are not available everywhere. Support depends on the website, device, browser and account-recovery process. You still need to protect your email and identity-provider accounts, maintain recovery methods for lost devices and secure the devices that hold your passkeys. For many people, the practical answer is to use both: passkeys where supported and a password manager for accounts that still require passwords.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Important edge cases
Banking and healthcare websites
Some services still impose outdated length or character restrictions. Use the strongest unique credential the service accepts, then enable every strong MFA option it provides. Do not weaken the password on other accounts to match the restrictive site.
Wi-Fi passwords
Replace the router’s default password. A long passphrase is usually easier to share with household members than a short, complex-looking string. Also change the router’s administrator password if it is separate from the Wi-Fi password.
Shared family accounts
Use a family password manager or the service’s delegated-access feature rather than sending credentials through chat or keeping them in an unencrypted notes file.
Work accounts
Follow your organization’s policy and use its approved password manager, single sign-on system or security key. Do not move company credentials into a personal vault without permission.
Security questions
Treat security-question answers as additional passwords. If a service requires them, use random answers and save them in the password manager rather than choosing information that can be found online.
Best Value
- Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More
- Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
- Enter one PIN number and have access to 400 accounts. Search function included.
- Unit auto locks for 30 minutes after 5 consecutive incorrect PIN attempts
- Includes mini stylus for easier keypad entry
Password-protected files
A password manager does not protect a file after the file has been copied elsewhere or the device is compromised. Use the file format’s current encryption features and protect the device itself.
Should you change passwords regularly?
Do not change every password on an arbitrary monthly or quarterly schedule just because a calendar reminder says so. Forced rotation often produces predictable changes such as adding a new number or year.
Change a password immediately when it is exposed, reused, shared improperly, suspected to be compromised, or covered by a breach notification. Replace weak passwords during a security review and upgrade accounts to MFA or passkeys when possible. NIST’s current guidance emphasizes length, blocklists of known-compromised passwords, password managers and MFA rather than routine expiration for its own sake.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Final password-security checklist
- Use a unique password for every account.
- Create manually chosen passwords of at least 15 characters.
- Prefer random generation from a reputable password manager.
- Avoid sequences, names, dates, keyboard paths, famous phrases and predictable substitutions.
- Secure email, identity-provider and password-manager accounts first.
- Enable MFA, preferring passkeys, security keys or authenticator apps where available.
- Use passkeys on supported services.
- Store recovery codes and emergency-access information securely.
- Respond immediately to breach alerts.
- Never assume a password is safe simply because it is absent from one published list.
Frequently Asked Questions
Is Password1! safe?
No. It combines a common word with the predictable capital letter, number and symbol pattern specifically warned about by NIST. Replace it with a unique, long credential generated by a password manager.
Is a 20-character password always safe?
No. Length helps, but a 20-character password can still be weak if it is reused, based on a famous phrase, exposed in a breach or entered into a phishing site.
What should I do after a data breach?
Change the affected password immediately, change it anywhere else it was reused, secure the associated email account, enable MFA and review active sessions and recovery methods.
Should I save passwords in my browser?
A reputable browser password manager can be safer than reuse or unencrypted notes. Keep the browser and device updated, protect the account with MFA and avoid autofill on suspicious domains.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →What if I forget my password-manager master password?
Use the manager’s documented recovery options, emergency access or stored recovery information. Do not create a second vault and abandon the first until you understand whether its data can be recovered.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

