'123456' and 'Password' Remain Worst Passwords of the Year for Fifth Consecutive Year

SplashData published its annual list of the worst passwords of the year this week, sourced from more than five million passwords leaked on the internet this year. Like previous years, 2018 saw numerous high-profile data leaks, but many people have continued to use easily guessable passwords for their online accounts.

autofillpasswordssetup

The new password autofill feature in iOS 12

For the fifth consecutive year, "123456" and "password" are the top two most popular passwords online. New entries on the list include "111111", "sunshine", "princess", "666666", "654321", and "donald" at number 23. SplashData CEO Morgan Slain discussed the list: "Hackers have great success using celebrity names, terms from pop culture and sports, and simple keyboard patterns to break into accounts online because they know so many people are using those easy-to-remember combinations."

The top 10 most popular passwords of 2018:

1) 123456
2) password
3) 123456789
4) 12345678
5) 12345
6) 111111
7) 1234567
8) sunshine
9) qwerty
10) iloveyou

Higher up the list, popular passwords include people's names like "daniel", "hannah", and "thomas"; pop culture references like "solo", "tigger", and "lakers"; random items like "cookie" and "banana"; birth years like "1990" and "1991"; and simple phrases like "whatever" and "test". As Slain explained, using super-simple phrases like these for any account online is a bad idea because it's so easy to guess what they are.

“Our hope by publishing this list each year is to convince people to take steps to protect themselves online,” says Slain. “It’s a real head-scratcher that with all the risks known, and with so many highly publicized hacks such as Marriott and the National Republican Congressional Committee, that people continue putting themselves at such risk year-after-year.”

In total, SplashData estimated that almost 10 percent of people have used at least one of the top 25 worst passwords on this year's list, and nearly 3 percent of people have used the worst password at one time, "123456". Most of the five million passwords that were leaked and evaluated for the report came from users in North America and Western Europe.

To help users stay safe, SplashData said that their passwords should be no shorter than twelve characters and have mixed types of characters in each one. Every log-in should have a different password, and investing in a password management app to store everything, generate random new passwords, and automatically log into websites is always a good idea.

Apple itself introduced a new password autofill feature in iOS 12 this year, making it easy to connect to third-party password apps and fill out your passwords throughout iOS. If you haven't tried it out yet, check out our guide on using the feature to find out how it works.

Popular Stories

2024 iPhone Boxes Feature

Apple Changes Trade-In Values for iPhones, iPads, Macs, and More

Thursday January 16, 2025 6:45 am PST by
Apple today adjusted estimated trade-in values for select iPhone, iPad, Mac, and Apple Watch models in the U.S., according to its website. Some values increased, while others decreased. The changes were not too significant, with most values rising or dropping by $5 to $50. We have outlined some examples below: Device New Value Old Value iPhone 15 Pro Max Up to $630 U ...
Generic iOS 19 Feature Mock Light

iOS 19 Leak Reveals All-New Design

Friday January 17, 2025 2:42 pm PST by
iOS 19 is still around six months away from being announced, but a new leak has allegedly revealed a completely redesigned Camera app. Based on footage it obtained, YouTube channel Front Page Tech shared a video showing what the new Camera app will apparently look like, with the key change being translucent menus for camera controls. Overall, the design of these menus looks similar to...
Generic iOS 18

Everything New in iOS 18.3 Beta 3

Thursday January 16, 2025 12:39 pm PST by
Apple provided the third beta of iOS 18.3 to developers today, and while the betas have so far been light on new features, the third beta makes some major changes to Notification Summaries and also tweaks a few other features. Notification Summary Changes Apple made multiple changes to Notification Summaries in response to complaints about inaccurate summaries of news headlines. For...
2024 App Store Awards

Apple Explains Why It Removed TikTok From the App Store in the U.S.

Sunday January 19, 2025 6:58 am PST by
Apple on late Saturday removed TikTok from the App Store in the U.S., and it has now explained why it was required to take this action. Last year, the U.S. passed a law that required Chinese company ByteDance to divest its ownership of TikTok due to potential national security risks, or else the platform would be banned. That law went into effect today, and companies like Apple and Google...
iPhone 17 Slim Feature Single Camera 1 Redux

'iPhone 17 Air' Launching Later This Year With These 10 New Features

Wednesday January 15, 2025 7:16 am PST by
While the so-called "iPhone 17 Air" is not expected to launch until September, there are already plenty of rumors about the "ultra-thin" device. Overall, the "iPhone 17 Air" is shaping up to be a mixed bag. Due to its thinness, the device is expected to have some limited specifications compared to the iPhone 17 Pro models, including only a single rear camera, only a single speaker, no SIM...
iPad Pro vs iPhone 17 Air Feature

Here's How Thin the iPhone 17 Air Might Be

Friday January 17, 2025 3:38 pm PST by
For the last several months, we've been hearing rumors about a redesigned version of the iPhone 17 that Apple might call the iPhone 17 "Air," or something along those lines. It's going to replace the iPhone 17 Plus as Apple's fourth iPhone option, and it will be offered alongside the iPhone 17, iPhone 17 Pro, and iPhone 17 Pro Max. We know the iPhone 17 Air is going to be super slim, but...
HomePod mini and Apple TV

Apple Expected to Launch 20+ Products This Year: Here's the Full List

Friday January 17, 2025 5:30 am PST by
2025 promises to be quite a big year for Apple, with the company rumored to be planning more than 20 product announcements this year. Apple's rumored smart home hub will be its second all-new product to launch in as many years, following the Apple Vision Pro headset last year. And of course, we will get several new iPhone and Apple Watch models, like every year. Beyond that, Apple could...
iPhone 17 Pro Dual Tone Horizontal Single Feature

iPhone 17 Rumored to Feature Major Thermal Design Upgrade

Friday January 17, 2025 4:33 am PST by
The iPhone 17 lineup will feature a vapor chamber heatsink to improve thermal performance, according to a new report. The news comes from Chinese tech news site MyDrivers, which claims that the entire iPhone 17 lineup, consisting of the iPhone 17, iPhone 17 Air, iPhone 17 Pro, and iPhone 17 Pro Max, will adopt the improved thermal heat spreader. Vapor chamber technology is already used...

Top Rated Comments

AngerDanger Avatar
80 months ago
How are people managing to get away with such simple passwords? I take the XKCD approach to password creation—a sentence comprised of nonsensical but easy to remember words. By the time I get done setting up an account, however, I've had to add a number, a capital letter, and a symbol. They only make my originally strong password harder for me to remember.

Score: 22 Votes (Like | Disagree)
Junipr Avatar
80 months ago
Older Coworkers: “I use one password for everything...”

Me: “Nice! 1Password is a great password management app”

OC: “No app, just the same password every time...”

Me: *facepalm*
Score: 13 Votes (Like | Disagree)
brofkand Avatar
80 months ago
Free password managers like iCloud Keychain, Bitwarden, etc., make remembering passwords obsolete. There is no excuse to have poor passwords in 2018.
[doublepost=1544799583][/doublepost]
How are people managing to get away with such simple passwords? I take the XKCD approach to password creation—a sentence comprised of nonsensical but easy to remember words. By the time I get done setting up an account, however, I've had to add a number, a capital letter, and a symbol. They only make my originally strong password harder for me to remember.

That was great advice before the advent of cross platform secure password managers, but today I'd say using a password manager to generate a random high entropy password is a better solution, ideally coupled with a second factor for sensitive data like banking or sites with payment methods attached.
Score: 10 Votes (Like | Disagree)
Claymore Avatar
80 months ago
Quick, change the combination on my luggage! Yes got in there first
Score: 7 Votes (Like | Disagree)
yaxomoxay Avatar
80 months ago
Mandatory video on password security:

Score: 7 Votes (Like | Disagree)
basical Avatar
80 months ago
Thank god mine didn't make the list.
000000
Score: 3 Votes (Like | Disagree)