search
Ask ACHR NEWS AI
cart
facebook twitter instagram linkedin youtube
  • Sign In
  • Subscribe
  • Sign Out
  • My Account
  • NEWS
  • TECHNOLOGY
    • Heating & Boilers
    • Cooling & Chillers
    • Pumps & Flow Controls
  • SECTORS
    • Commercial
    • Health Care
    • Data Center
    • Educational Facilities
  • DESIGN | CONSTRUCTION
  • OTHER TOPICS
    • High-Performance Buildings & Automation
    • Ventilation and IAQ
    • Commissioning
    • HVAC Retrofits
  • TODAY’S BOILER
    • Today’s Boiler Archives
    • Today’s Boiler Digital Edition
  • MORE
    • Case Studies
    • Podcasts
    • Videos
    • Directory
    • Webinars
    • ES NEWS Store
    • White Papers
  • SIGN UP
  • Back to The NEWS
Engineered Systems NEWSHVAC Engineering SectorsData Center HVAC

“123456” is the Most Common Password in the US in 2023

Passwords used for streaming services are the weakest, study reveals

By Mission Critical Magazine Staff
Passwords
(Image by Kris from Pixabay)
November 16, 2023

In 2023, "123456" was the most common password among Americans, as revealed by the fifth annual NordPass study. In addition to the 200 most common passwords worldwide and comparison among 35 countries, this year the study explored what passwords people use for different services, and whether they vary or not.

 

Passwords Americans loved in 2023 — the usual suspects and global trends

Amongst the 20 most common passwords in the United States (US), which are listed below, are both the same-old worst offenders and some newcomers. The full list with global passwords, separate lists for 35 countries, and eight platform types are available here: https://nordpass.com/most-common-passwords-list/.

Top 20 Passwords in the US in 2023

  1. 123456
  2. password
  3. admin
  4. 1234
  5. UNKNOWN
  6. 12345678
  7. 123456789
  8. 12345
  9. abc123
  10. Password
  11. Password1
  12. password1
  13. 12345678910
  14. 1q2w3e4r
  15. 1234567
  16. shitbird
  17. 1234567890
  18. 123123
  19. reset
  20. qwerty

While passwords in every country, including the US, vary greatly, there are some clear global trends.

  1. The study concludes that people use the weakest passwords for their streaming accounts. In contrast, the strongest passwords are used for financial accounts.
  2. Internet users often go for a relevant brand’s or company’s name when creating a password. For example, on smartphone apps, people tend to use easy-to-remember passwords, such as “iPhone6s,” “Samsung1,” “1messenger,” and similar.
  3. “123456” is the most common password in the US this year. Worldwide, it has also repeatedly proved its popularity. Throughout the past five years, it held the number one position four times.

Other numerical sequences are also used to secure online accounts. This year, almost a third (31%) of the world's* most popular passwords consist of purely numerical sequences, such as “123456789,” “12345,” “000000,” and others.

  1. Using insulting words in passwords is apparently a common way to express an emotion, but definitely not a secure one. The creative “shitbird” is a highly popular password in the US this year. Last year, “fuckyou” and “asshole” were topping the list.
  2. Internet users in the US learned at least one thing from last year’s study results: “guest” is not a secure password. While this word was the most used among Americans last year, it has now not made it on to the list.
  3. Instead of improving password creation habits, internet users have gone in another direction by sticking to already pre-configured passwords. The word “admin”, which, most likely, is one of the passwords that people do not bother changing, made it to the top among this year’s most common passwords in most of the researched countries, including the US.
  4. As many as 70% of the passwords in this year’s global list can be cracked in less than a second.

*Data presented in this study does not represent absolute password usage worldwide. Researchers analyzed a sample of passwords extracted from publicly available sources, including those on the dark web.

 

Streaming Accounts are Protected with the Weakest Passwords

The study also revealed what kind of passwords people use for different platforms and whether they vary in strength.

The weakest passwords are used to secure streaming accounts. According to Tomas Smalakys, chief technology officer (CTO) at NordPass, this could be associated with people jointly managing shared accounts and using easy-to-remember passwords for convenience.

Unsurprisingly, people pay more attention to accounts they associate directly with money. Therefore, they use the strongest passwords for their financial services.

 

Hackers Target Passwords Saved on Browsers

To find out about passwords internet users employ for different platforms, researchers analyzed a 6.6 TB database of passwords, exposed by various stealer malware, which experts consider a huge threat to people’s cybersecurity.

Malware attacks are particularly dangerous because malware logs contain a vast amount of information about the victim. For example, malware can steal information saved in your browsers, such as passwords and other credentials, source website cookies, autofill data. In addition to that, it can also steal files from its victim's computer, as well as system details such as OS version or IP address.

“The scariest part is that victims might not even realize that their computer is infected. Bad actors tend to hide malware in well-crafted phishing emails, imitating a legitimate organization, such as your bank or your company,” says Smalakys.

 

The Future of Passwords

Throughout the five years of NordPass conducting this research, “123456” was the top password four times. According to Smalakys, this is a clear sign that change in authentication is essential.

Passkeys are a new form of authentication. The essence of this technology is that the user doesn’t need to come up with a password — everything is done automatically. When joining a website that supports passkeys, the user's device generates a pair of related keys — public and private. The private key is saved on the device itself and the public key is stored on the website’s server. Without each other, they are useless. If the user is successfully identified by their biometrics, the passkeys are matched and the user successfully signs in.

“This technology will help eliminate lousy passwords, thus making users more secure. However, as with every innovation, passwordless authentication will not be adopted overnight. Being amongst the first password managers to offer this technology, we can see that users are more and more curious to test it out. However, there’s still a lot of work to be done and password security still remains a matter of today,” says Smalakys.

 

Tips for Secure Credentials’ Management

While passkeys are still making their way to the mainstream, password and cybersecurity hygiene remains of utmost importance.

  1. Create long and complex passwords. “123456 just doesn’t cut it anymore,” says Smalakys. Easy-to-guess passwords essentially equal unlocked house doors, which is why he advises using 20 character-long random passwords containing uppercase and lowercase letters, symbols, and numbers.
  2. Avoid storing your secrets on your browser and adopt a password manager. With stealer malware attacks targeting credentials on browsers, third-party password management software are considered a more secure choice for credential storage.
  3. Start adopting passkeys. An increasing number of websites are now offering the option to access accounts with passkeys instead of passwords. While passkeys won’t completely replace passwords just yet, they are definitely the future of authentication.
  4. Stay vigilant. In order to protect yourself from stealer malware, pay close attention to anything that you download onto your computer. Malware is often distributed via phishing emails — so learn how to recognize them.

Research methodology: The list of passwords was compiled in partnership with independent researchers specializing in research of cybersecurity incidents. They evaluated a 4.3TB database extracted from various publicly available sources, including those on the dark web. No personal data was acquired or purchased by NordPass to conduct this study.

Researchers classified the data into various verticals, which allowed them to perform a statistical analysis based on countries. NordPass exclusively received only statistical information from the researchers, which gives no reference to internet users’ personal data.

Additionally, third-party researchers analyzed another 6.6 TB database of passwords. They were stolen by various stealer malware, such as Redline, Vidar, Taurus, Raccoon, Azorult, and Cryptbot. Malware logs include not only passwords, but also the source website. Researchers categorized the most popular passwords per platform type and shared statistically aggregated findings with NordPass.

 

About NordPass

NordPass is a password manager for both business and consumer clients. It’s powered by the latest technology for the utmost security. Developed with affordability, simplicity, and ease of use in mind, NordPass allows users to access passwords securely on desktop, mobile, and browsers. All passwords are encrypted on the device, so only the user can access them. NordPass was created by the experts behind NordVPN — the advanced security and privacy app. For more information: nordpass.com.

This article was originally posted on www.missioncriticalmagazine.com.

KEYWORDS: cybersecurity Data Centers and HVACR

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • HVAC-enrollment

    The Trades Are Back: HVACR Programs See Nearly 30% Enrollment Spike

    A new wave of future technicians is entering the pipeline.  
    Training and Education
    By: Matt Jachman
  • 2025 Top 40 Under 40

    2025 Top 40 Under 40 HVACR Professionals List

    The 11th annual Top 40 Under 40 list highlights those...
    News
    By: Hannah Belloli-Oster
  • LG Ductless Mini-Split Systems

    The 9 Types of Heat Pumps

    As the U.S. moves toward electrification, heat pumps are...
    Ground Source Heat Pumps
    By: Joanna R. Turpin

More Videos

Today's Boiler

Spring 2026 Issue

Today's Boiler - Spring 2026 Cover

Read More from Today's Boiler

Case in Point Logo

Smarter Hydronic Design for Data Centers - Free Webinar - January 22, 2026

Related Articles

  • Installation steps

    6 of the Most Common HVAC Installation Mistakes Killing System Performance

    See More
  • Nov. 30, 2009: Construction Index Is the Most Positive in Over a Year

    See More
  • General Services Administration Says LEED System Is the Most Credible

    See More

Related Products

See More Products
  • new cover.jpg

    Profit is An Attitude: The Strategies You Need to Optimize Profits

  • Lessons Learned in a Boiler Room: A common sense approach to servicing and installing commercial boilers

See More Products

Related Directories

  • The Malco Group

    The Malco Group is a leading manufacturer and distributor of high-quality HVACR solutions that power the success of businesses, trade pros end-users, and homes across North America.
  • Women in HVACR

    Women in HVACR are an international organization for Women in the Heating, Ventilation, Air Conditioning and Refrigeration industry. Women in HVACR exist to improve the lives of our members by providing professional avenues to connect with other women.
  • The Whalen Co.

    The Whalen Company is the pioneering manufacturer of HVAC vertical stack riser heat-exchanger fan coil units and water-source heat pumps for hotels, apartments and other multi-story buildings.
×

Sign Up. Stay Informed.

The #1 trusted source for the HVACR industry since 1926

SUBSCRIBE
  • RESOURCES
    • Advertise
    • Contact Us
    • Advisory Board
    • Classifieds
    • Submit a Letter
    • Directories
    • Store
  • ACCOUNT CENTER
    • Create an Account
    • Start a Subscription
    • Manage My Account
    • Sign Up for Newsletters
    • Visit Customer Service
    • Update Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • Instagram
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing