Close Menu
TechurzTechurz
    What's Hot

    Asian AI startups launch Mythos-like models as Anthropic’s export ban drags on

    June 27, 2026

    Corgi, the buzzy Y Combinator-backed insurance tech startup, says it didn’t steal an open source product

    June 26, 2026

    OpenAI poaches Uber India chief to lead its biggest market outside the US

    June 26, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Asian AI startups launch Mythos-like models as Anthropic’s export ban drags on
    • Corgi, the buzzy Y Combinator-backed insurance tech startup, says it didn’t steal an open source product
    • OpenAI poaches Uber India chief to lead its biggest market outside the US
    • Early Bird pricing ends tonight for Founder Summit
    • Robotaxis drive miles just to get cleaned and charged; this new startup wants to fix that
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Security - A whopping 94% of leaked passwords are not unique – will you people ever learn?
    Security

    A whopping 94% of leaked passwords are not unique – will you people ever learn?

    TechurzBy TechurzMay 5, 2025No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A whopping 94% of leaked passwords are not unique - will you people ever learn?
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Elyse Betters Picaro / ZDNET

    Do you ever use “123456,” “admin,” or “password” as the password for a personal or work account? If so, you’re unfortunately not alone and are placing yourself and your employer at risk.

    Also: 10 passkey survival tips: Prepare for your passwordless future now

    Published last Friday by security news and research outlet Cybernews, a new study of more than 19 billion leaked passwords shows that people still rely on patterns that leave them vulnerable to attack and compromise. 

    For the study, Cybernews looked at credentials leaked from 200 different incidents over the past 12 months. Using various cyber intelligence tools, the outlet was able to determine such factors as password length, character composition, and the use of special characters and numbers.

    Table of contents
    1 The most common (and lazy) passwords still in use
    2 Widespread epidemic
    3 How to better protect yourself and your company

    The most common (and lazy) passwords still in use

    Based on the analysis, lazy passwords such as “1234,” “123456,” “password,” and “admin” are still quite common. Cybernews found “1234” in almost 4% of passwords, more than 727 million. With two extra digits, “123456” appeared in 338 million passwords. Both “password” and “123456” have been among the most popular passwords since at least 2011.

    Also: Why multi-factor authentication is absolutely essential in 2025

    Cybernews

    One problem is that many systems and products come with default passwords, such as routers with “admin” as both the username and password. Too many people never bother to change the defaults, even in a business or industrial environment, leaving their accounts and equipment vulnerable to attack.

    Also: 7 password rules security experts live by in 2025 – the last one might surprise you

    “The ‘default password’ problem remains one of the most persistent and dangerous patterns in leaked credential datasets,” said Neringa Macijauskaitė, information security researcher at Cybernews. “Entries for ‘password’ (56 million) and ‘admin’ (53 million) reveal that users overwhelmingly rely on simple, predictable defaults. Attackers, too, prioritize them, making these passwords among the least secure.”

    Widespread epidemic

    A whopping 94% of passwords were reused or duplicated, and among the more than 19 billion passwords examined, only 1 billion, or 6%, were considered unique and therefore relatively secure.

    “We’re facing a widespread epidemic of weak password reuse,” Macijauskaitė said. “Only 6% of passwords are unique, leaving other users highly vulnerable to dictionary attacks. For most, security hangs by the thread of two-factor authentication — if it’s even enabled.”

    Beyond the usual culprits, other words and terms often pop up as passwords. Many people choose a name as their password or at least as part of it. The name “Ana” appeared in 1% of leaked passwords, or 178 million. Pop culture is also a popular theme. Cybernews uncovered millions of people with passwords such as “Mario,” “Joker,” “Batman,” and “Thor.”

    Positive words like “love,” “dream,” “joy,” and “freedom” were found in millions of passwords. On the flip side, profanity finds its way into passwords, with several curse words used by millions of people.

    Also: Biometrics vs. passcodes: What lawyers say if you’re worried about warrantless phone searches

    Other frequently used passwords include countries, cities, US states, food, popular brands, nature, animals, and seasons or months. Among cities, the most popular password is “Rome.” In the animal kingdom, “lion” and “fox” are common. Many people choose food or drink for passwords, with top choices such as “Tea,” “Apple,” “Rice,” “Banana,” and “Orange.”

    Next, Cybernews found that many people (42%) use 8- to 10-character passwords, with eight characters being the most popular. This is likely because many online systems don’t allow passwords shorter than eight characters. Around 27% use only lowercase letters and numbers, not uppercase letters or special characters.

    Devising a weak password or reusing the same one is quick and simple — and easy to remember. But at what cost?

    The simpler and more common the password, the less effort cybercriminals spend cracking it. Past studies have found that certain passwords can be cracked in less than a minute. Hackers who capture a password from one site will try it at other sites. That leaves you, all your accounts, and even your company exposed to compromise.

    Also: The best password managers: Expert tested

    “The prevalence of weak, reused, and simple passwords across platforms significantly increases the risk of cyberattacks,” Macijauskaitė added. “If you reuse passwords across multiple platforms, a breach in one system can compromise the security of other accounts, creating a domino effect. Even without any compromise, hackers can exploit common password patterns.”

    How to better protect yourself and your company

    With passwords still necessary and still difficult to create and use, what can you do to better protect yourself and your company? Cybernews offers several tips.

    1. Use a password manager. Such tools can automatically create, store, and apply strong passwords for every account and site you use.
    2. Use strong and complex passwords. Make sure that your password has at least 12 characters and that it includes lowercase and uppercase letters, numbers, and at least one special character. Avoid using any common or recognizable words, names, or other strings.
    3. Enable multi-factor authentication. Set up MFA whenever and wherever it’s available. This form of authentication provides a second layer of security. Even if your password is stolen, the attacker can’t access your account without the necessary MFA code.
    4. Enforce password policies. Organizations should enforce policies that require passwords of at least 12 characters with a mix of uppercase and lowercase letters, numbers, and special characters.
    5. Review access controls. Organizations should regularly review their access controls and run security audits. Shore up any weaknesses you find to reduce the chances of credentials and data being leaked.
    6. Monitor for credential leaks. Organizations should use the right tools and technologies to detect leaked credentials in real time. You can then block access or require new passwords for any targeted accounts.

    Get the morning’s top stories in your inbox each day with our Tech Today newsletter.

    leaked learn passwords people unique whopping
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleApple might not release the iPhone 18 until 2027
    Next Article Take a Tour of All the Essential Features in ChatGPT
    Techurz
    • Website

    Related Posts

    Opinion

    Zest launches a restaurant discovery app powered by where people actually eat

    June 10, 2026
    Opinion

    Rocket engine startup Impulse raises $500 million to hire people, not AI

    June 2, 2026
    Opinion

    Focused Energy raises whopping $240M Series A for laser-powered fusion tech

    June 2, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622

    Future of Digital Privacy and Security: 7 Truths Nobody Tells You

    May 25, 202619
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.