It’s time for SplashData to release its annual list of the most common passwords of 2016, but first, let’s start with a password list from Keeper Security.

Most Common Passwords of 2016 by Keeper Security

The company analyzed over 10 million passwords publicly available before publishing a list of the 25 most common passwords of 2016. Keeper Security didn’t include leaked passwords if the breaches were announced that year but occurred before 2016.

  1. 123456
  2. 123456789
  3. qwerty
  4. 12345678
  5. 111111
  6. 1234567890
  7. 1234567
  8. password
  9. 123123
  10. 987654321
  11. qwertyuiop
  12. mynoob
  13. 123321
  14. 666666
  15. 18atcskd2w
  16. 7777777
  17. 1q2w3e4r
  18. 654321
  19. 555555
  20. 3rjs1la7qe
  21. google
  22. 1q2w3e4r5t
  23. 123qwe
  24. zxcvbnm
  25. 1q2w3e

Of course, if your password is one of the passwords in this list (or any public list, for that matter), then you should change your password immediately!

Most Common Passwords of 2016 by SplashData

The 2016 edition of the 25 most common passwords made up more than 10% of the surveyed passwords, with the most common password of 2016, “123456”, making up 4%. Does this shock anyone anymore?

The numbers in parentheses denote the position change in the password list. New refers to a new position on the list, 0 refers to the same position (unchanged), positive numbers mean the entry has gone up, and finally, a negative number means the entry went down the list.

  1. 123456 (0)
  2. password (0)
  3. 12345 (2)
  4. 12345678 (-1)
  5. football (2)
  6. qwerty (-2)
  7. 1234567890 (5)
  8. 1234567 (1)
  9. princess (12)
  10. 1234 (-2)
  11. login (9)
  12. welcome (-1)
  13. solo (10)
  14. abc123 (-1)
  15. admin (New)
  16. 121212 (New)
  17. flower (New)
  18. passw0rd (6)
  19. dragon (-3)
  20. sunshine (New)
  21. master (-4)
  22. hottie (New)
  23. loveme (New)
  24. zaq1zaq1 (New)
  25. password1 (New)

Comparison of the Most Common Passwords from 2011 to 2016 by SplashData

Since 2011, SplashData has published a list of the 25 most common passwords each year. The list is based on data examined from millions of passwords leaked in data breaches, mostly in North America and Western Europe, year over year.

Rank201620152014201320122011
1123456123456123456123456passwordpassword
2passwordpasswordpasswordpassword123456123456
3123451234567812345123456781234567812345678
412345678qwerty12345678qwertyabc123qwerty
5football12345qwertyabc123qwertyabc123
6qwerty123456789123456789123456789monkeymonkey
71234567890football1234111111letmein1234567
812345671234baseball1234567dragonletmein
9princess1234567dragoniloveyou111111trustno1
101234baseballfootballadobe123baseballdragon
11loginwelcome1234567123123iloveyoubaseball
12welcome1234567890monkeyadmintrustno1111111
13soloabc123letmein12345678901234567iloveyou
14abc123111111abc123letmeinsunshinemaster
15admin1qaz2wsx111111photoshopmastersunshine
16121212dragonmustang1234123123ashley
17flowermasteraccessmonkeywelcomebailey
18passw0rdmonkeyshadowshadowshadowpassw0rd
19dragonletmeinmastersunshineashleyshadow
20sunshineloginmichael12345football123123
21masterprincesssupermanpassword1jesus654321
22hottieqwertyuiop696969princessmichaelsuperman
23lovemesolo123123azertyninjaqazwsx
24zaq1zaq1passw0rdbatmantrustno1mustangmichael
25password1starwarstrustno10password1Football
Rank201620152014201320122011
SplashData Most Common Passwords 2011-2016

Comparison of the Most Common Passwords from 2016 – Both Research Sources

RankSplashDataKeeper
1123456123456
2password12345679
312345qwerty
41234567812345678
5football111111
6qwerty1234567890
712345678901234567
81234567password
9princess123123
101234987654321
11loginqwertyuiop
12welcomemynoob
13solo123321
14abc123666666
15admin18atcskd2w
161212127777777
17flower1q2w3e4r
18passw0rd654321
19dragon555555
20sunshine3rjs1la7qe
21mastergoogle
22hottie1q2w3e4r5t
23loveme123qwe
24zaq1zaq1zxcvbnm
25password11q2w3e
RankSplashDataKeeper
Most Common Passwords in 2016 from SplashData and Keeper Security

Most Common Passwords of 2016 Observations

Did you notice some seemingly “secure” passwords on the Keeper list like “18atcskd2w” and “3rjs1la7qe” and wondered why? The answer is potentially bots. Bots that spam countless sites, free email providers, forums, and more and use the same passwords. The goal is to set up dummy accounts to facilitate spam and phishing attacks.

The most popular password, making up nearly 17 percent of the 10 million passwords the company analyzed, was “123456.” This is also on the SplashData list. “Password” was also among the top 10 passwords.

Seven of the top 15 passwords are six characters or shorter, which means they are cracked in seconds (or less). Keeper Security advises users to select a password that’s more than 6 characters long and contain all variation of characters. It’s worth mentioning that many organizations have adopted 8 to 12 character requirements, as 6 characters just aren’t enough anymore.

“What really perplexed us is that so many website operators are not enforcing password security best practices,” he wrote. “While it’s important for users to be aware of risks, a sizable minority are never going to take the time or effort to protect themselves. IT administrators and website operators must do the job for them.”

Darren Guccione, Keeper Security Co-founder and CEO

The company also suggests avoiding using single words found in the dictionary. Two of the most common password cracking techniques are dictionary cracks and brute force cracks. These attacks attempt to crack passwords by trying known passwords, single dictionary terms, and personal information like sports teams, family names, phone numbers, and birthdays.

As you see passwords on screen and on paper that read “1q2w3e4r” and “123qwe,” you know you found an attempt by users to create unpredictable passwords by using keyboard patterns. Unfortunately, these users only bought themselves a few seconds, as password crackers know to look for sequential key variations.

And finally, as you look through these password lists, you realize that little has changed year over year. In fact, little has changed over the last decade. Education is essential, but it isn’t everything. You need to set guardrails and enforce password complexity and history.

Additional Sources:

To compare against last year’s passwords, check out our previous Most Common Passwords of 2015 post.