Skip to Main Content

Millions using 123456 as password, security study finds


Millions of people are using easy-to-guess passwords on sensitive accounts, suggests a study. 

secure-your-account-with-a-strong-password.jpg

The analysis by the UK's National Cyber Security Centre (NCSC) found 123456 was the most widely-used password on breached accounts.

The study helped to uncover the gaps in cyber-knowledge that could leave people in danger of being exploited.

The NCSC said people should string three random but memorable words together to use as a strong password.

Sensitive data

For its first cyber-survey, the NCSC analysed public databases of breached accounts to see which words, phrases and strings people used.

Top of the list was 123456, appearing in more than 23 million passwords. The second-most popular string, 123456789, was not much harder to crack, while others in the top five included "qwerty", "password" and 1111111.

The most common name to be used in passwords was Ashley, followed by Michael, Daniel, Jessica and Charlie.

When it comes to Premier League football teams in guessable passwords, Liverpool are champions and Chelsea are second. Blink-182 topped the charts of music acts.

People who use well-known words or names for a password put themselves people at risk of being hacked, said Dr Ian Levy, technical director of the NCSC.

"Nobody should protect sensitive data with something that can be guessed, like their first name, local football team or favourite band," he said.

Hard to guess

The NCSC study also quizzed people about their security habits and fears.

It found that 42% expected to lose money to online fraud and only 15% said they felt confident that they knew enough to protect themselves online.

It found that fewer than half of those questioned used a separate, hard-to-guess password for their main email account.

Top Tips:

  • Use three random but memorable words together with punctuation and numbers to form a strong password.
  • Also use 2FA (Two-Factor Authentication) to stop remote access in case you're password if ever lost by a service provider!

 

 

https://www.bbc.co.uk/news/technology-47974583?intlink_from_url=https://www.bbc.co.uk/news/topics/cz4pr2gd85qt/cyber-security&link_location=live-reporting-story