Easy-to-guess passwords push authentication evolution

Easy-to-guess passwords push authentication evolution

Estimated reading time: 4 minutes · Last updated:

A fresh analysis by the Alan Boswell Group of Have I Been Pwned data shows how common weak secrets remain and why authentication is changing. The single string '123456' appears nearly 210 million times in exposed lists, while the literal Password was recorded more than 52 million times, Admin 42 million and qwerty over 30 million. Those counts, plus almost 4 million instances of the word monkey, power automated credential-stuffing attacks, industry figures warn. Security professionals quoted in the dataset say blocking known leaked passwords, rolling out multi-factor authentication and moving users onto password managers and passkeys are the practical responses.

They are already sitting in leaked password lists, and criminals can use automated tools to try them across different sites.

Heath Alexander-Bew, personal lines director at Alan Boswell Group

Key takeaways

  • Most exposed password: The Alan Boswell Group found the string '123456' nearly 210 million times in Have I Been Pwned data.
  • Other common entries: 'Password' appears more than 52 million times and 'Admin' appears 42 million times in the same dataset.
  • Keyboard patterns and oddities: 'qwerty' shows up over 30 million times, and nearly 4 million exposed passwords were simply 'monkey'.
  • Expert-recommended mitigations: Heath Alexander-Bew of Alan Boswell Group urges blocking common leaked passwords, enforcing multi-factor authentication and promoting password managers.
  • Authentication trend: Kathryn Linford of Insight IT expects passkeys, biometrics and trusted devices to become more common and to replace many passwords.

How widespread weak passwords remain

The Alan Boswell Group cross-referenced leaked credentials with the Have I Been Pwned collection to quantify reuse and obvious choices. That dataset shows '123456' as the clear leader at nearly 210 million occurrences. Other plain forms remain widespread: the literal Password was logged more than 52 million times, Admin 42 million, and qwerty over 30 million. The analysis also highlights predictable selections drawn from personal life and popular culture: the name Daniel tops the list of personal-name passwords, football is the dominant sport, Liverpool is the most common team, and Superman is the most common fictional character used as a password.

Those raw counts matter because they are reusable. Once a password string appears in a widely circulated leak, attackers do not need to guess it anew; they feed the list into automation and try the same values across multiple sites and services. The scale — hundreds of millions for a single string — raises the odds of a successful credential-stuffing hit against reused logins.

Why breached lists enable immediate attacks and how to limit them

Leaked-password collections reduce the step an attacker must take: instead of guessing, they replay known values. Heath Alexander-Bew, personal lines director at Alan Boswell Group, warns that attackers can try exposed passwords across sites with automated tools, which is the core mechanism behind credential stuffing. That method is especially effective where people reuse passwords or use short, common strings.

Practices to blunt that exposure are concrete and repeatable. Alexander-Bew recommends that organisations block the most common leaked passwords at signup and password-change flows, deploy multi-factor authentication for sensitive services, and require or encourage password managers so each account has a unique, strong secret. He also emphasises post-compromise checks: after changing a password, users and admins should verify recovery addresses and email-forwarding rules, because an intruder who already had access may have left persistence mechanisms.

Where authentication is heading: passkeys, biometrics and trusted devices

Several practitioners quoted in the dataset view passwords as a legacy control that will shrink in use. Kathryn Linford, owner of Insight IT, says passwords are becoming obsolete and expects passkeys, fingerprints, face scans and trusted-device signals to replace passwords for many organisations. Those methods shift authentication from something you remember to something you possess or are, which removes the problem of shared, recycled or easy-to-guess strings.

Adoption comes with operational choices. Enterprises need to stitch passkey and biometric options into account recovery and help-desk procedures, and they must maintain fallback paths for users on older devices. For now, Linford and others continue to recommend password managers for individuals and MFA for business accounts as interim steps that reduce exposure while infrastructure and processes evolve toward stronger, non-secret-based authentication.

Top exposed passwords in the Alan Boswell Group analysis of Have I Been Pwned data
Password Times seen Context
123456 nearly 210 million most common
Password more than 52 million literal word
Admin 42 million administrative term
qwerty more than 30 million keyboard pattern
monkey nearly 4 million common single word

The case for and against a rapid move off passwords

The case for

  • Wider passkey and biometric support in browsers and platforms will lower the friction of replacing passwords for end users and reduce the value of leaked lists.
  • Organisations can substantially cut account-takeover risk by blocking known leaked passwords, enforcing MFA and offering password managers, measures already recommended by Alan Boswell Group spokespeople.

The case against

  • Leaked lists are persistent and circulate through underground markets; they will keep enabling credential-stuffing against legacy systems and reuse-prone users for the foreseeable future.
  • Operational gaps — recovery contacts, forwarding rules and device compatibility — can preserve attacker access even after a password change, slowing the benefits that new authentication methods deliver.

What to be careful about

  • Credential-stuffing attacks using the leaked strings cited in the analysis, as Heath Alexander-Bew warns.
  • Account takeover persisting after a password change if recovery details or forwarding rules remain controlled by an attacker.
  • Slow enterprise migration paths that leave older systems and help desks as attack vectors during a transition to passkeys and biometrics.

The bottom line

The counts in the Alan Boswell Group analysis underline a simple fact: predictable, reused strings remain abundant and useful to attackers. Blocking those known values, enforcing multi-factor authentication and getting users onto password managers cut the immediate attack surface. Over time, wider deployment of passkeys and biometric signals should reduce reliance on memorised secrets, but the shift requires operational changes in recovery, help-desk workflows and device support to ensure it delivers the promised safety gains.

What to watch

  • Watch for major service providers to announce enterprise or consumer passkey rollouts; no date has been set.
  • Watch for companies to publicise blocking policies for known leaked passwords or enforced MFA on sensitive accounts; no date has been set.

Frequently asked questions

Which passwords are most common in leaked lists?

'123456' is the top entry, appearing nearly 210 million times in the analysis cited; the literal Password appears more than 52 million times, Admin 42 million and qwerty over 30 million.

What immediate steps should organisations take?

Alan Boswell Group advisers recommend blocking the most common leaked passwords at sign-up and password changes, deploying multi-factor authentication and encouraging password manager use to ensure unique, strong credentials.

Will passwords disappear?

Kathryn Linford of Insight IT says passwords are becoming obsolete and expects passkeys, biometrics and trusted devices to replace many passwords, though enterprises must manage compatibility and recovery during the transition.



Share:

Categories

Newest course every month

Advertise your offline course to a wider audience with our landing page.

You May Also Like

Easy-to-guess passwords are widespread: '123456' shows up nearly 210 million times; experts recommend blocking leaked passwords, MFA and passkeys.
Cybersecurity 2026: how identity, telemetry, human risk and AI-native operations are reshaping detection and response across cloud, endpoints and devices.
Rob Bonta told Gadi Schwartz on 2 October 2026 he issued an investigative subpoena to OpenAI, citing cybersecurity risks; the...