ZeroHour
Huntresspublished ()ingested

The 20 Most Common Passwords Hackers Target in 2026

infoPhishing & fraudimportance 12
AI summary · glm-5.3-flash

Huntress details the 20 most common passwords of 2026 and how attackers use brute force, spraying, and credential stuffing against weak credentials.

Huntress published an awareness piece based on NordPass's seventh annual list of the 200 most commonly used passwords, compiled from exposed data in cyberattacks across 44 countries. The top passwords remain simple sequences and variants such as "123456", "admin", "password", and "P@ssw0rd", all crackable in under a second. The article explains four password attack types: brute force, password spraying, credential stuffing, and dictionary attacks. Huntress cites its own data showing more than 1 in 4 IT professionals consider employees' password habits their biggest weakness, and recommends avoiding common passwords, not reusing credentials, and combining letters, numbers, and symbols.

  • Top 2026 passwords include "123456", "admin", "password", and simple variants
  • NordPass list is based on exposed data from attacks in 44 countries
  • Explains brute force, password spraying, credential stuffing, and dictionary attacks
  • Over 1 in 4 IT professionals say employee password habits are their biggest weakness
  • Recommends unique, complex passwords across all accounts
Full article1,422 words · extracted from huntress.com · click to collapse

Are you using the same password you came up with on your very first login, however many years ago?

You’re not alone. About 68% of people admit to reusing their password across multiple accounts. That’s extra risky if yours is one of the most common passwords.

If your password made this list, it’s time to consider a change. Using easy-to-guess and common passwords is almost as bad as writing your credentials down on a sticky note that you leave on your monitor. We don’t recommend it.

Learn about the most common passwords, the password attacks they enable, and how to create a strong password that holds up against today’s threats.

A list of the most common passwords, including “123456”, “admin”, and “12345678”.

A list of the most common passwords in 2026

NordPass’s 7th edition of their top 200 most commonly used passwords is based on data exposed during cyberattacks from 44 different countries. The results? Well, they’re not very unique, which isn’t surprising considering password statistics show that 46% of people are more likely to choose an easy-to-remember password than a secure one.

NordPass included generational data in their most recent report, which showed few major differences between Gen Z and baby boomers. Some, shall we say, noteworthy variations include Gen Z having top passwords like “skibidi” and “assword” in their top 10, while baby boomers have a number of women’s first names like “maria” and “monica,” to take on the Mambo No. 5.

Here are the most common passwords across the globe and age ranges, all of which take less than a second for a threat actor to crack.

Rank

Password

1

123456

2

admin

3

12345678

4

123456789

5

12345

6

password

7

Aa123456

8

1234567890

9

Pass@123

10

admin123

11

1234567

12

123123

13

111111

14

12345678910

15

P@ssw0rd

16

Password

17

Aa@123456

18

admintelecom

19

Admin@123

20

112233

How weak passwords enable password attacks

Using common passwords makes you an easy target for password attacks. In fact, 35% of people blame weak passwords for getting hacked. Many cyberattacks focus on using credentials to gain access to a system, account, or network to cause havoc.

Here are some examples of cyber threats that target passwords:

Brute force attacks

A brute force attack is a password attack where automated tools rapidly cycle through possible credential combinations, or manually guess based on personal information gathered on the target.

The effectiveness of this attack hinges on password complexity; simple passwords are cracked quickly, while complex ones can take too long, forcing attackers to move on.

Password spraying

Password spraying is a type of cyberattack where attackers try to access numerous accounts using just a few commonly used passwords. Instead of trying many password variations on a single account, they “spray” one password across a large number of accounts, before moving on to try another common password.

This tactic helps them avoid triggering account lockout mechanisms that would occur with traditional brute force attacks. Essentially, attackers take advantage of the fact that many people use weak, predictable passwords.

Credential stuffing

Credential stuffing is a password attack where threat actors use stolen credentials from previous data breaches to gain unauthorized access to other online accounts. They exploit the fact that many people reuse the same credentials across multiple platforms.

Automated tools quickly test these stolen credentials against various websites and services, aiming to find matches. If a match is found, the attacker can access the associated account.

Dictionary attack

A dictionary attack attempts to crack passwords by testing words and number combinations from a list of common terms. Automated tools try these words and variations across accounts.

These attacks target easily guessed passwords, like common words or simple number combinations. Unlike brute force, it focuses on likely choices, making it efficient but vulnerable to complex passwords.

What Huntress sees firsthand

Huntress data shows that password usage is one of the top concerns of IT professionals, with more than 1 in 4 saying it’s their employees’ biggest weakness. As bad actors use AI in cyberattacks more often, protecting your credentials becomes increasingly important.

“People really underestimate how important password security is. It may seem like a given, but the more complex your password is, the more difficult your account is to access,” says Lindsey O’Donnell-Welch, Principal Technical Community Engagement Writer at Huntress. “That doesn’t even factor in things like being sure to change your password after a breach and using different passwords, all of which improve security.”

Priorities for 2027 (and always) should include enforcing strong credentials and protections so threat actors can’t easily gain access to multiple accounts. When data is compromised on one account, whether that’s from a hack or a large-scale data breach, and if a user is using the same password on all of their accounts, then they’re all now potentially compromised.

That might sound scary, but there are many ways to protect credentials; most of which are quite easy.

The do's and don'ts of creating a strong password, comparing “password” against a random 16-character password.

How to create a strong password policy

Knowing how to create a strong password is only half the battle of keeping your accounts safe. A strong password policy means applying those habits consistently across every account. Here are the essentials:

  1. Avoid any of the most common passwords: Using widely known passwords like “123456” or “admin” is like leaving your front door unlocked and wide open. Threat actors have access to vast databases of these common passwords, and automated tools can crack them in mere seconds, granting them easy access to your accounts.
  2. Don’t repeat passwords: Reusing passwords across multiple accounts creates a single point of failure. If one of your accounts is compromised, all accounts sharing that password become vulnerable. This domino effect can lead to widespread security breaches and significant data loss.
  3. Use a combination of letters, numbers, and characters: Strong passwords are built on complexity. Using both uppercase and lowercase letters, as well as numbers and special characters, makes your passwords significantly harder for threat actors to crack.
  4. Enable multi-factor authentication (MFA): Activate MFA whenever possible. This adds an extra layer of security by requiring a second form of verification.
  5. Be wary of phishing attempts: Be cautious of suspicious emails or messages that ask for your password. Legitimate services will never request your password via email.
  6. Check for breached passwords: Use online tools to see if your passwords have been compromised in past data breaches. If so, change them immediately.
  7. Think passphrases, not passwords: A password like P@$$w0rd! looks intimidating, but modern AI-powered cracking tools can break it in under a minute. The smarter approach is a passphrase: four or more random, unrelated words strung together.
  8. Use a password manager as your single source of truth: No one can reliably memorize 100 unique 16-character strings, and trying leads directly to the Password Reuse Trap. One breach at a minor shopping site becomes the key to your bank account when you recycle passwords. A dedicated password manager such as LastPass, 1Password, or Dashlane solves this completely.

Protect your business from password attacks

Avoiding the most common passwords is a strong first step, but protecting your business from password attacks requires continuous identity monitoring across your entire organization.

We understand what threats like credential theft and unauthorized access mean for your business, and we’re here to help. Huntress has you covered with managed ITDR, detecting and responding to identity-based threats and password attacks across your organization 24/7.

FAQ

How can I protect my business from password-based attacks?

To use a sports cliché, the best defense is good offense. Prioritize teaching employees about strong passwords, not reusing passwords, and implementing multi-factor authentication. Huntress Security Awareness Training can help reduce security incidents while also limiting the training burden on your team.

What is the most common password?

“123456” is the most commonly used password, with more than 21.6 million people using it globally.

What are the top 10 most common passwords?

The top 10 most common passwords are “123456”, “admin”, “12345678”, “123456789”, “12345”, “password”, “Aa123456”, “1234567890”, “Pass@123”, and “admin123”.

What is the easiest password to crack?

Any of the most commonly used passwords are extremely easy to crack, including “123456”, “admin”, and “password”.

What is the strongest password?

A strong password or passphrase is long, unique, and random. It should be at least 16 characters long, not reused across multiple accounts, and consist of a random assortment of letters, numbers, and symbols with no personal meaning.

What are the most common password attacks?

Common password attacks include brute force attacks, password spraying, and credential stuffing. These attacks typically rely on people reusing their passwords across multiple accounts.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.huntress.com/blog/most-common-passwords