These are the 25 worst passwords of 2015

Some people will never learn.

Look on the bright side! There’s one good thing that comes out of all those website breaches every year: Security researchers get to comb through all those lists of usernames and passwords to remind us just how bad most of our passwords are. Now that we’re well into 2016, password management company SplashData just released its annual round-up of the worst passwords of 2015.

The report is based on more than 2 million passwords that leaked online during the year. One trend the company found in 2015 is that while users are coming up with longer passwords (that’s good), they are simple and not random (that’s bad). Two examples the company points to are ‘1234567890’ and ‘qwertyuiop’. One just uses every number key and the other uses the top row of keys on a standard QWERTY keyboard.

The more common password faux pas remain including basic numerical passwords and sports terms. Star Wars: The Force Awakens was big news in 2015, and it appears quite a few people went with Star Wars-themed passwords such as ‘starwars,’ ‘solo,’ and ‘princess.’

Star Wars fans may be Jedis in other areas, but when it comes to passwords they’re still Padawans.

Here’s Splashdata's complete list of the 25 worst passwords for 2015, with their ranking from 2014 in brackets:

  1. 123456 (Unchanged)
  2. password (Unchanged)
  3. 12345678 (Up 1)
  4. qwerty (Up 1)
  5. 12345 (Down 2)
  6. 123456789 (Unchanged)
  7. football (Up 3)
  8. 1234 (Down 1)
  9. 1234567 (Up 2)
  10. baseball (Down 2)
  11. welcome (New)
  12. 1234567890 (New)
  13. abc123 (Up 1)
  14. 111111 (Up 1)
  15. 1qaz2wsx (New)
  16. dragon (Down 7)
  17. master (Up 2)
  18. monkey (Down 6)
  19. letmein (Down 6)
  20. login (New)
  21. princess (New)
  22. qwertyuiop (New)
  23. solo (New)
  24. passw0rd (New)
  25. starwars (New)

Save yourself

There’s no doubt about it, managing passwords is a pain, but they're the best security measure available right now. Tech companies are working to change that, but at the moment there’s no getting around the need for good, strong passwords.

The best thing to do is create long, random passwords that are hard to guess. Your passwords should use a combination of letters (including different cases), numbers, and symbols if possible. Also make sure you use a unique password for every major account you have including banking, email, Paypal, social networks, and any website that has your credit card data, such as Amazon.

If you have trouble remembering those new passwords then use a password manager such as KeePass, LastPass, Dashlane, or SplashID.

You should also use multi-factor authentication whenever it’s offered to keep your accounts extra safe. That way if you ever lose control of your password malicious hackers won’t be able to break into your account without the numeric code generated on your smartphone. Most major services support multi-factor authentication, including Amazon, Facebook, Gmail, Microsoft, and Twitter.

Keeping your accounts secure isn’t simple, but if you stick to the basics it’s not that hard—and sticking to best practices will save you from headaches should your account credentials end up in the hands of hackers.

Join the CSO newsletter!

Error: Please check your email address.

Tags passwordsworst passwords

More about FacebookMicrosoftSplashdataTwitter

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Ian Paul

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts

Market Place