'123456' and 'Password' Remain Worst Passwords of the Year for Fifth Consecutive Year

SplashData published its annual list of the worst passwords of the year this week, sourced from more than five million passwords leaked on the internet this year. Like previous years, 2018 saw numerous high-profile data leaks, but many people have continued to use easily guessable passwords for their online accounts.

autofillpasswordssetup

The new password autofill feature in iOS 12

For the fifth consecutive year, "123456" and "password" are the top two most popular passwords online. New entries on the list include "111111", "sunshine", "princess", "666666", "654321", and "donald" at number 23. SplashData CEO Morgan Slain discussed the list: "Hackers have great success using celebrity names, terms from pop culture and sports, and simple keyboard patterns to break into accounts online because they know so many people are using those easy-to-remember combinations."

The top 10 most popular passwords of 2018:

1) 123456
2) password
3) 123456789
4) 12345678
5) 12345
6) 111111
7) 1234567
8) sunshine
9) qwerty
10) iloveyou

Higher up the list, popular passwords include people's names like "daniel", "hannah", and "thomas"; pop culture references like "solo", "tigger", and "lakers"; random items like "cookie" and "banana"; birth years like "1990" and "1991"; and simple phrases like "whatever" and "test". As Slain explained, using super-simple phrases like these for any account online is a bad idea because it's so easy to guess what they are.

“Our hope by publishing this list each year is to convince people to take steps to protect themselves online,” says Slain. “It’s a real head-scratcher that with all the risks known, and with so many highly publicized hacks such as Marriott and the National Republican Congressional Committee, that people continue putting themselves at such risk year-after-year.”

In total, SplashData estimated that almost 10 percent of people have used at least one of the top 25 worst passwords on this year's list, and nearly 3 percent of people have used the worst password at one time, "123456". Most of the five million passwords that were leaked and evaluated for the report came from users in North America and Western Europe.

To help users stay safe, SplashData said that their passwords should be no shorter than twelve characters and have mixed types of characters in each one. Every log-in should have a different password, and investing in a password management app to store everything, generate random new passwords, and automatically log into websites is always a good idea.

Apple itself introduced a new password autofill feature in iOS 12 this year, making it easy to connect to third-party password apps and fill out your passwords throughout iOS. If you haven't tried it out yet, check out our guide on using the feature to find out how it works.

Popular Stories

maxresdefault

Apple Shows Off a Key Reason to Upgrade to the iPhone 17

Saturday February 7, 2026 9:26 am PST by
Apple today shared an ad that shows how the upgraded Center Stage front camera on the latest iPhones improves the process of taking a group selfie. "Watch how the new front facing camera on iPhone 17 Pro takes group selfies that automatically expand and rotate as more people come into frame," says Apple. While the ad is focused on the iPhone 17 Pro and iPhone 17 Pro Max, the regular iPhone...
apple wallet drivers license feature iPhone 15 pro

Apple Says These 7 U.S. States Plan to Offer iPhone Driver's Licenses

Monday February 9, 2026 6:24 am PST by
In select U.S. states, residents can add their driver's license or state ID to the Apple Wallet app on the iPhone and Apple Watch, and then use it to display proof of identity or age at select airports and businesses, and in select apps. The feature is currently available in 13 U.S. states and Puerto Rico, and it is expected to launch in at least seven more in the future. To set up the...
14 inch MacBook Pro Keyboard

New MacBook Pros Could Now Arrive in March

Sunday February 8, 2026 6:02 am PST by
New MacBook Pro models with the M5 Pro and M5 Max chips could arrive as soon as Monday, March 2, according to Bloomberg's Mark Gurman. In today's "Power On" newsletter, Gurman said that the release of new MacBook Pro models is tied to the release of macOS Tahoe 26.3. The launch is said to be slated for as early as the week of March 2. He added that the M4 Pro and M4 Max models on sale today...
wwdc sans text feature

Apple Rumored to Announce New Product on February 19

Thursday February 5, 2026 12:22 pm PST by
Apple plans to announce the iPhone 17e on Thursday, February 19, according to Macwelt, the German equivalent of Macworld. The report, citing industry sources, is available in English on Macworld. Apple announced the iPhone 16e on Wednesday, February 19 last year, so the iPhone 17e would be unveiled exactly one year later if this rumor is accurate. It is quite uncommon for Apple to unveil...
Apple Logo Zoomed

Apple Expected to Launch These 10+ Products Over the Coming Months

Tuesday February 10, 2026 6:33 am PST by
It has been a slow start to 2026 for Apple product launches, with only a new AirTag and a special Apple Watch band released so far. We are still waiting for MacBook Pro models with M5 Pro and M5 Max chips, the iPhone 17e, a lower-cost MacBook with an iPhone chip, long-rumored updates to the Apple TV and HomePod mini, and much more. Apple is expected to release/update the following products...

Top Rated Comments

AngerDanger Avatar
94 months ago
How are people managing to get away with such simple passwords? I take the XKCD approach to password creation—a sentence comprised of nonsensical but easy to remember words. By the time I get done setting up an account, however, I've had to add a number, a capital letter, and a symbol. They only make my originally strong password harder for me to remember.

Score: 22 Votes (Like | Disagree)
Junipr Avatar
94 months ago
Older Coworkers: “I use one password for everything...”

Me: “Nice! 1Password is a great password management app”

OC: “No app, just the same password every time...”

Me: *facepalm*
Score: 13 Votes (Like | Disagree)
brofkand Avatar
94 months ago
Free password managers like iCloud Keychain, Bitwarden, etc., make remembering passwords obsolete. There is no excuse to have poor passwords in 2018.
[doublepost=1544799583][/doublepost]
How are people managing to get away with such simple passwords? I take the XKCD approach to password creation—a sentence comprised of nonsensical but easy to remember words. By the time I get done setting up an account, however, I've had to add a number, a capital letter, and a symbol. They only make my originally strong password harder for me to remember.

That was great advice before the advent of cross platform secure password managers, but today I'd say using a password manager to generate a random high entropy password is a better solution, ideally coupled with a second factor for sensitive data like banking or sites with payment methods attached.
Score: 10 Votes (Like | Disagree)
Claymore Avatar
94 months ago
Quick, change the combination on my luggage! Yes got in there first
Score: 7 Votes (Like | Disagree)
yaxomoxay Avatar
94 months ago
Mandatory video on password security:

Score: 7 Votes (Like | Disagree)
basical Avatar
94 months ago
Thank god mine didn't make the list.
000000
Score: 3 Votes (Like | Disagree)