A recent analysis of over two billion leaked passwords revealed that easily guessable and weak passwords such as 123456, admin, and password remain among the most commonly used worldwide. Variations like Aa123456, Aa@123456, and sequential keyboard patterns such as qwerty and 1q2w3e4r also feature prominently in the top 100, highlighting persistent poor password hygiene among users. The study found that a quarter of the most common passwords consist solely of numbers, and 38% contain the string 123, making them highly susceptible to brute-force and guessing attacks.
Complementing these findings, research into the top 1,000 most-visited websites showed that 42% have no minimum password length requirements, and only five enforce strong password policies that include length, special characters, and case sensitivity. Additionally, 11% of these sites have no password creation requirements at all, and only 2% support passkeys as a secure alternative. The lack of robust password enforcement on major websites, especially in sectors like government and healthcare, perpetuates the use of weak passwords and increases the risk of account compromise.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
SC Media reported that nearly half of the top 1,000 websites had no password length requirements, underscoring weak password policy enforcement across major online services.
Comparitech published its 2025 study showing that highly predictable passwords such as "123456," "admin," and "password" remain common, with many top passwords consisting of numeric strings or containing "123." The findings highlighted ongoing poor password hygiene and prompted recommendations for passkeys, long passphrases, password managers, and stronger organizational password policies.
Comparitech conducted a 2025 analysis of more than two billion passwords exposed on breach forums to identify the 100 most common passwords and broader password-use patterns.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.