The 20 Most Common Passwords Hackers Target in 2026
Huntress details the 20 most common passwords of 2026 and how attackers use brute force, spraying, and credential stuffing against weak credentials.
Huntress published an awareness piece based on NordPass's seventh annual list of the 200 most commonly used passwords, compiled from exposed data in cyberattacks across 44 countries. The top passwords remain simple sequences and variants such as "123456", "admin", "password", and "P@ssw0rd", all crackable in under a second. The article explains four password attack types: brute force, password spraying, credential stuffing, and dictionary attacks. Huntress cites its own data showing more than 1 in 4 IT professionals consider employees' password habits their biggest weakness, and recommends avoiding common passwords, not reusing credentials, and combining letters, numbers, and symbols.
- Top 2026 passwords include "123456", "admin", "password", and simple variants
- NordPass list is based on exposed data from attacks in 44 countries
- Explains brute force, password spraying, credential stuffing, and dictionary attacks
- Over 1 in 4 IT professionals say employee password habits are their biggest weakness
- Recommends unique, complex passwords across all accounts
Full article1,422 words · extracted from huntress.com · click to collapse
Are you using the same password you came up with on your very first login, however many years ago?
You’re not alone. About 68% of people admit to reusing their password across multiple accounts. That’s extra risky if yours is one of the most common passwords.
If your password made this list, it’s time to consider a change. Using easy-to-guess and common passwords is almost as bad as writing your credentials down on a sticky note that you leave on your monitor. We don’t recommend it.
Learn about the most common passwords, the password attacks they enable, and how to create a strong password that holds up against today’s threats.
A list of the most common passwords in 2026
NordPass’s 7th edition of their top 200 most commonly used passwords is based on data exposed during cyberattacks from 44 different countries. The results? Well, they’re not very unique, which isn’t surprising considering password statistics show that 46% of people are more likely to choose an easy-to-remember password than a secure one.
NordPass included generational data in their most recent report, which showed few major differences between Gen Z and baby boomers. Some, shall we say, noteworthy variations include Gen Z having top passwords like “skibidi” and “assword” in their top 10, while baby boomers have a number of women’s first names like “maria” and “monica,” to take on the Mambo No. 5.
Here are the most common passwords across the globe and age ranges, all of which take less than a second for a threat actor to crack.
Rank | Password |
1 | 123456 |
2 | admin |
3 | 12345678 |
4 | 123456789 |
5 | 12345 |
6 | password |
7 | Aa123456 |
8 | 1234567890 |
9 | Pass@123 |
10 | admin123 |
11 | 1234567 |
12 | 123123 |
13 | 111111 |
14 | 12345678910 |
15 | P@ssw0rd |
16 | Password |
17 | Aa@123456 |
18 | admintelecom |
19 | Admin@123 |
20 | 112233 |
How weak passwords enable password attacks
Using common passwords makes you an easy target for password attacks. In fact, 35% of people blame weak passwords for getting hacked. Many cyberattacks focus on using credentials to gain access to a system, account, or network to cause havoc.
Here are some examples of cyber threats that target passwords:
Brute force attacks
A brute force attack is a password attack where automated tools rapidly cycle through possible credential combinations, or manually guess based on personal information gathered on the target.
The effectiveness of this attack hinges on password complexity; simple passwords are cracked quickly, while complex ones can take too long, forcing attackers to move on.
Password spraying
Password spraying is a type of cyberattack where attackers try to access numerous accounts using just a few commonly used passwords. Instead of trying many password variations on a single account, they “spray” one password across a large number of accounts, before moving on to try another common password.
This tactic helps them avoid triggering account lockout mechanisms that would occur with traditional brute force attacks. Essentially, attackers take advantage of the fact that many people use weak, predictable passwords.
Credential stuffing
Credential stuffing is a password attack where threat actors use stolen credentials from previous data breaches to gain unauthorized access to other online accounts. They exploit the fact that many people reuse the same credentials across multiple platforms.
Automated tools quickly test these stolen credentials against various websites and services, aiming to find matches. If a match is found, the attacker can access the associated account.
Dictionary attack
A dictionary attack attempts to crack passwords by testing words and number combinations from a list of common terms. Automated tools try these words and variations across accounts.
These attacks target easily guessed passwords, like common words or simple number combinations. Unlike brute force, it focuses on likely choices, making it efficient but vulnerable to complex passwords.
What Huntress sees firsthand
Huntress data shows that password usage is one of the top concerns of IT professionals, with more than 1 in 4 saying it’s their employees’ biggest weakness. As bad actors use AI in cyberattacks more often, protecting your credentials becomes increasingly important.
“People really underestimate how important password security is. It may seem like a given, but the more complex your password is, the more difficult your account is to access,” says Lindsey O’Donnell-Welch, Principal Technical Community Engagement Writer at Huntress. “That doesn’t even factor in things like being sure to change your password after a breach and using different passwords, all of which improve security.”
Priorities for 2027 (and always) should include enforcing strong credentials and protections so threat actors can’t easily gain access to multiple accounts. When data is compromised on one account, whether that’s from a hack or a large-scale data breach, and if a user is using the same password on all of their accounts, then they’re all now potentially compromised.
That might sound scary, but there are many ways to protect credentials; most of which are quite easy.
How to create a strong password policy
Knowing how to create a strong password is only half the battle of keeping your accounts safe. A strong password policy means applying those habits consistently across every account. Here are the essentials:
- Avoid any of the most common passwords: Using widely known passwords like “123456” or “admin” is like leaving your front door unlocked and wide open. Threat actors have access to vast databases of these common passwords, and automated tools can crack them in mere seconds, granting them easy access to your accounts.
- Don’t repeat passwords: Reusing passwords across multiple accounts creates a single point of failure. If one of your accounts is compromised, all accounts sharing that password become vulnerable. This domino effect can lead to widespread security breaches and significant data loss.
- Use a combination of letters, numbers, and characters: Strong passwords are built on complexity. Using both uppercase and lowercase letters, as well as numbers and special characters, makes your passwords significantly harder for threat actors to crack.
- Enable multi-factor authentication (MFA): Activate MFA whenever possible. This adds an extra layer of security by requiring a second form of verification.
- Be wary of phishing attempts: Be cautious of suspicious emails or messages that ask for your password. Legitimate services will never request your password via email.
- Check for breached passwords: Use online tools to see if your passwords have been compromised in past data breaches. If so, change them immediately.
- Think passphrases, not passwords: A password like P@$$w0rd! looks intimidating, but modern AI-powered cracking tools can break it in under a minute. The smarter approach is a passphrase: four or more random, unrelated words strung together.
- Use a password manager as your single source of truth: No one can reliably memorize 100 unique 16-character strings, and trying leads directly to the Password Reuse Trap. One breach at a minor shopping site becomes the key to your bank account when you recycle passwords. A dedicated password manager such as LastPass, 1Password, or Dashlane solves this completely.
Protect your business from password attacks
Avoiding the most common passwords is a strong first step, but protecting your business from password attacks requires continuous identity monitoring across your entire organization.
We understand what threats like credential theft and unauthorized access mean for your business, and we’re here to help. Huntress has you covered with managed ITDR, detecting and responding to identity-based threats and password attacks across your organization 24/7.
FAQ
How can I protect my business from password-based attacks?
To use a sports cliché, the best defense is good offense. Prioritize teaching employees about strong passwords, not reusing passwords, and implementing multi-factor authentication. Huntress Security Awareness Training can help reduce security incidents while also limiting the training burden on your team.
What is the most common password?
“123456” is the most commonly used password, with more than 21.6 million people using it globally.
What are the top 10 most common passwords?
The top 10 most common passwords are “123456”, “admin”, “12345678”, “123456789”, “12345”, “password”, “Aa123456”, “1234567890”, “Pass@123”, and “admin123”.
What is the easiest password to crack?
Any of the most commonly used passwords are extremely easy to crack, including “123456”, “admin”, and “password”.
What is the strongest password?
A strong password or passphrase is long, unique, and random. It should be at least 16 characters long, not reused across multiple accounts, and consist of a random assortment of letters, numbers, and symbols with no personal meaning.
What are the most common password attacks?
Common password attacks include brute force attacks, password spraying, and credential stuffing. These attacks typically rely on people reusing their passwords across multiple accounts.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.huntress.com/blog/most-common-passwords