'123456' and 'Password' Remain Worst Passwords of the Year for Fifth Consecutive Year

SplashData published its annual list of the worst passwords of the year this week, sourced from more than five million passwords leaked on the internet this year. Like previous years, 2018 saw numerous high-profile data leaks, but many people have continued to use easily guessable passwords for their online accounts.

autofillpasswordssetup

The new password autofill feature in iOS 12

For the fifth consecutive year, "123456" and "password" are the top two most popular passwords online. New entries on the list include "111111", "sunshine", "princess", "666666", "654321", and "donald" at number 23. SplashData CEO Morgan Slain discussed the list: "Hackers have great success using celebrity names, terms from pop culture and sports, and simple keyboard patterns to break into accounts online because they know so many people are using those easy-to-remember combinations."

The top 10 most popular passwords of 2018:

1) 123456
2) password
3) 123456789
4) 12345678
5) 12345
6) 111111
7) 1234567
8) sunshine
9) qwerty
10) iloveyou

Higher up the list, popular passwords include people's names like "daniel", "hannah", and "thomas"; pop culture references like "solo", "tigger", and "lakers"; random items like "cookie" and "banana"; birth years like "1990" and "1991"; and simple phrases like "whatever" and "test". As Slain explained, using super-simple phrases like these for any account online is a bad idea because it's so easy to guess what they are.

“Our hope by publishing this list each year is to convince people to take steps to protect themselves online,” says Slain. “It’s a real head-scratcher that with all the risks known, and with so many highly publicized hacks such as Marriott and the National Republican Congressional Committee, that people continue putting themselves at such risk year-after-year.”

In total, SplashData estimated that almost 10 percent of people have used at least one of the top 25 worst passwords on this year's list, and nearly 3 percent of people have used the worst password at one time, "123456". Most of the five million passwords that were leaked and evaluated for the report came from users in North America and Western Europe.

To help users stay safe, SplashData said that their passwords should be no shorter than twelve characters and have mixed types of characters in each one. Every log-in should have a different password, and investing in a password management app to store everything, generate random new passwords, and automatically log into websites is always a good idea.

Apple itself introduced a new password autofill feature in iOS 12 this year, making it easy to connect to third-party password apps and fill out your passwords throughout iOS. If you haven't tried it out yet, check out our guide on using the feature to find out how it works.

Popular Stories

New Things Your iPhone Can Do in iOS 18

20 New Things Your iPhone Can Do in iOS 18.2

Monday December 16, 2024 8:55 am PST by
Apple released iOS 18.2 in the second week of December, bringing the second round of Apple Intelligence features to iPhone 15 Pro and iPhone 16 models. This update brings several major advancements to Apple's AI integration, including completely new image generation tools and a range of Visual Intelligence-based enhancements. Apple has added a handful of new non-AI related feature controls as...
iphone 16 apple intelligence

Apple Drops Plans for iPhone Hardware Subscription Service

Wednesday December 18, 2024 11:39 am PST by
Apple is no longer planning to launch a hardware subscription service that would let customers "subscribe" to get a new iPhone each year, reports Bloomberg's Mark Gurman. Gurman first shared rumors about Apple's work on a hardware subscription service back in 2022, and at the time, he said that Apple wanted to develop a simple system that would allow customers to pay a monthly fee to gain...
iPhone 17 Pro Dual Tone Feature 1

iPhone 17 Pro Rumored to Stick With 'Triangular' Camera Design

Wednesday December 18, 2024 2:36 am PST by
Contrary to recent reports, the iPhone 17 Pro will not feature a horizontal camera layout, according to the leaker known as "Instant Digital." In a new post on Weibo, the leaker said that a source has confirmed that while the appearance of the back of the iPhone 17 Pro has indeed changed, the layout of the three cameras is "still triangular," rather than the "horizontal bar spread on the...
elevation lab airtag battery

Your AirTag's Battery Will Last for Up to 10 Years With Elevation Lab's New TimeCapsule Enclosure

Wednesday December 18, 2024 10:05 am PST by
Elevation Lab today announced the launch of TimeCapsule, an innovative and simple solution for increasing the battery life of Apple's AirTag. Priced at $20, TimeCapsule is an AirTag enclosure that houses two AA batteries that offer 14x more battery capacity than the CR2032 battery that the AirTag runs on. It works by attaching the AirTag's upper housing to the built-in custom contact in the...
apple tv 4k yellow bg feature

New Apple TV Rumored to Launch Next Year With These Features

Tuesday December 17, 2024 9:02 am PST by
The current Apple TV 4K was released more than two years ago, so the streaming device is becoming due for a hardware upgrade soon. Fortunately, it was recently rumored that a new Apple TV will launch at some point next year. Below, we recap rumors about the next-generation Apple TV. Bloomberg's Mark Gurman last week reported that Apple has been working on its own combined Wi-Fi and...
blackmagic vision pro

Blackmagic Debuts $30K 3D Camera for Capturing Video for Vision Pro

Monday December 16, 2024 4:17 pm PST by
Blackmagic today announced that its URSA Cine Immersive camera is now available for pre-order, with deliveries set to start late in the first quarter of 2025. Blackmagic says that this is the world's first commercial camera system designed to capture 3D content for the Vision Pro. The URSA Cine Immersive camera was first introduced in June, but it has not been available for purchase until...
mac pro creativity

Apple Launched the Controversial 'Trashcan' Mac Pro 11 Years Ago Today

Thursday December 19, 2024 7:00 pm PST by
Apple launched the controversial "trashcan" Mac Pro eleven years ago today, introducing one of its most criticized designs that persisted through a period of widespread discontentment with the Mac lineup. The redesign took the Mac Pro in an entirely new direction, spearheaded by a polished aluminum cylindrical design that became unofficially dubbed the "trashcan" in the Mac community. All of ...
iPhone 17 Slim Feature

'iPhone 17 Air' With 'Major' Design Changes and 19-Inch MacBook Detailed in New Report

Sunday December 15, 2024 9:47 am PST by
Apple is planning a series of "major design" and "format changes" for iPhones over the next few years, according to The Wall Street Journal's Aaron Tilley and Yang Jie. The paywalled report published today corroborated the widely-rumored "iPhone 17 Air" with an "ultrathin" design that is thinner than current iPhone models. The report did not mention a specific measurement, but previous...

Top Rated Comments

AngerDanger Avatar
79 months ago
How are people managing to get away with such simple passwords? I take the XKCD approach to password creation—a sentence comprised of nonsensical but easy to remember words. By the time I get done setting up an account, however, I've had to add a number, a capital letter, and a symbol. They only make my originally strong password harder for me to remember.

Score: 22 Votes (Like | Disagree)
Junipr Avatar
79 months ago
Older Coworkers: “I use one password for everything...”

Me: “Nice! 1Password is a great password management app”

OC: “No app, just the same password every time...”

Me: *facepalm*
Score: 13 Votes (Like | Disagree)
brofkand Avatar
79 months ago
Free password managers like iCloud Keychain, Bitwarden, etc., make remembering passwords obsolete. There is no excuse to have poor passwords in 2018.
[doublepost=1544799583][/doublepost]
How are people managing to get away with such simple passwords? I take the XKCD approach to password creation—a sentence comprised of nonsensical but easy to remember words. By the time I get done setting up an account, however, I've had to add a number, a capital letter, and a symbol. They only make my originally strong password harder for me to remember.

That was great advice before the advent of cross platform secure password managers, but today I'd say using a password manager to generate a random high entropy password is a better solution, ideally coupled with a second factor for sensitive data like banking or sites with payment methods attached.
Score: 10 Votes (Like | Disagree)
Claymore Avatar
79 months ago
Quick, change the combination on my luggage! Yes got in there first
Score: 7 Votes (Like | Disagree)
yaxomoxay Avatar
79 months ago
Mandatory video on password security:

Score: 7 Votes (Like | Disagree)
basical Avatar
79 months ago
Thank god mine didn't make the list.
000000
Score: 3 Votes (Like | Disagree)