Business & Tech
'Password,' '123456' Again Top 25 Worst Passwords List
SplashData releases its annual tally, and says folks continue to be at risk with weak, easily guessable sign-ins.

Information courtesy of SplashData:
SplashData has announced its annual list of the 25 most common passwords found on the Internet β thus making them the βWorst Passwordsβ that will expose anybody to being hacked or having their identities stolen.
In its fourth annual report, compiled from more than 3.3 million leaked passwords during the year, β123456βand βpasswordβ continue to hold the top two spots that they have held each year since the first list in 2011.
Find out what's happening in Millbraefor free with the latest updates from Patch.
Other passwords in the top 10 include βqwerty,β βdragon,β and βfootball.β
As in past yearsβ lists, simple numerical passwords remain common, with nine of the top 25 passwords on the 2014 list comprised of numbers only.
Find out what's happening in Millbraefor free with the latest updates from Patch.
Passwords appearing for the first time on SplashDataβs list include β696969β and βbatman.β
While Valentineβs Day is less than a month away, βiloveyouβ is one of the nine passwords from 2013 to fall off the 2014 list.
According to SplashData, the passwords evaluated for the 2014 list were mostly held by users in North America and Western Europe.
In 2014, millions of passwords from Russian accounts were also leaked, but these passwords were not included in the analysis.
SplashDataβs list of frequently used passwords shows that many people continue to put themselves at risk by using weak, easily guessable passwords.
βPasswords based on simple patterns on your keyboard remain popular despite how weak they are,β said Morgan Slain, CEO of SplashData. βAny password using numbers alone should be avoided, especially sequences. As more websites require stronger passwords or combinations of letters and numbers, longer keyboard patterns are becoming common passwords, and they are still not secure.β
For example, users should avoid a sequence such as βqwertyuiop,β which is the top row of letters on a standard keyboard, or β1qaz2wsxβ which comprises the first two βcolumnsβ of numbers and letters on a keyboard.
Other tips from a review of this yearβs Worst Passwords List include:
- Donβt use a favorite sport as your password β βbaseballβ and βfootballβ are in top 10, and βhockey,β βsoccerβ and βgolferβ are in the top 100. Donβt use a favorite team either, as βyankees,β βeagles,β βsteelers,β βrangers,β and βlakersβ are all in the top 100.
- Donβt use your birthday or especially just your birth year -- 1989, 1990, 1991, and 1992 are all in the top 100.
- While baby name books are popular for naming children, donβt use them as sources for picking passwords. Common names such as βmichael,β βjennifer,β βthomas,β βjordan,β βhunter,β βmichelle,β βcharlie,β βandrew,β and βdanielβ are all in the top 50.
Also in the top 100 are swear words and phrases, hobbies, famous athletes, car brands, and film names.
This is the first year that SplashData has collaborated on the list with Mark Burnett, online security expert and author of βPerfect Passwordsβ ( www.xato.net).
βThe bad news from my research is that this yearβs most commonly used passwords are pretty consistent with prior years,β Burnett said. βThe good news is that it appears that more people are moving away from using these passwords. In 2014, the top 25 passwords represented about 2.2% of passwords exposed. While still frightening, thatβs the lowest percentage of people using the most common passwords I have seen in recent studies.β
SplashData, provider of the SplashID line of password management applications, releases its annual list in an effort to encourage the adoption of stronger passwords.
Slain says, βAs always, we hope that with more publicity about how risky it is to use weak passwords, more people will start taking simple steps to protect themselves by using stronger passwords and using different passwords for different websites.β
Presenting SplashDataβs βWorst Passwords of 2014β:
Rank........ Password........ Change from 2013
1................. 123456 .............Unchanged
2 ................ password........ Unchanged
3 ............... 12345 ............... Up 17
4 ............... 12345678 ......... Down 1
5 ............... qwerty .............. Down 1
6 ............... 123456789 ....... Unchanged
7 .............. 1234 .................. Up 9
8 ................baseball ............New
9 ...............dragon ...............New
10 ............ football ..............New
11..............1234567 .............Down 4
12 ............monkey .............. Up 5
13............. letmein .............. Up 1
14 ............ abc123 ...............Down 9
15 ............ 111111 ..............Down 8
16 ............ mustang ........... New
17 ............ access ............... New
18 ............ shadow ............. Unchanged
19 ............ master .............. New
20 .............michael ............. New
21 ............superman...........New
22 ........... 696969 ...............New
23 ........... 123123 .............. Down 12
24 ............batman ..............New
25 ............ trustno1 ........... Down 1
SplashData offers three simple tips to be safer from hackers online:
- Use passwords of eight characters or more with mixed types of characters.
- Avoid using the same username/password combination for multiple websites.
- Use a password manager, such as SplashID, to organize and protect passwords, generate random passwords, and automatically log into websites.
Get more local news delivered straight to your inbox. Sign up for free Patch newsletters and alerts.