'123456' Named 2014's Worst Password of the Year

Despite the multitude of password management apps that are available, like 1Password and LastPass, many people continue to use easily guessable words and number strings to protect their sensitive information.

One of the most popular passwords in 2014, for example, was "123456," according to a list of leaked 2014 passwords gathered by SplashData (via Re/code). The second most used password was "password," followed by "12345," "12345678," and "qwerty." Both "123456" and "password" have also been popular in past years, ranking as the top two most commonly used passwords in 2013.

Similar number strings were the sixth and seventh most popular 2014 passwords, followed by the words "baseball," "football," and "dragon."

worstpasswordsof2014

"Passwords based on simple patterns on your keyboard remain popular despite how weak they are," said Morgan Slain, CEO of SplashData. "Any password using numbers alone should be avoided, especially sequences. As more websites require stronger passwords or combinations of letters and numbers, longer keyboard patterns are becoming common passwords, and they are still not secure."

To get its list of the worst passwords in 2014, its fourth annual year of collecting password data, SplashData looked at more than 3.3 million passwords that were leaked across 2014. Passwords came primarily from users in North America and Western Europe.

Based on the data that it gathered, SplashData recommends against using keyboard sequences like "1qaz2wsx" or "qwertyuiop," and it advises users not to use a favorite sport. Baseball and football made the top 10 list of most common passwords, while hockey, soccer, and golfer were in the top 100. Team-based passwords like Yankees, Eagles, Steelers, Rangers, and Lakers also made the top 100 list.

Birthdays and birth years are also not recommended, nor are names, with common monikers like Michael, Jennifer, Thomas, and Jordan listed within the top 50 most commonly used passwords. Swear words, phrases, hobbies, athletes, car brands, and film names were also heavily featured in SplashData's top 100 list.

Using a password management app like SplashID, 1Password, or LastPass is highly recommended, to generate random passwords that are used for a single site and that are more secure than self-generated words, numbers, and phrases.

Widely publicized data leaks across 2013 and 2014 seem to have spurred more people to choose stronger passwords, as the top 25 passwords represented just 2.2 percent of passwords exposed. Along with the well-known iCloud breach, many companies including Home Depot, Target, and Staples saw major data leaks.

Popular Stories

wwdc sans text feature

Apple Rumored to Announce New Product on February 19

Thursday February 5, 2026 12:22 pm PST by
Apple plans to announce the iPhone 17e on Thursday, February 19, according to Macwelt, the German equivalent of Macworld. The report, citing industry sources, is available in English on Macworld. Apple announced the iPhone 16e on Wednesday, February 19 last year, so the iPhone 17e would be unveiled exactly one year later if this rumor is accurate. It is quite uncommon for Apple to unveil...
maxresdefault

Apple Shows Off a Key Reason to Upgrade to the iPhone 17

Saturday February 7, 2026 9:26 am PST by
Apple today shared an ad that shows how the upgraded Center Stage front camera on the latest iPhones improves the process of taking a group selfie. "Watch how the new front facing camera on iPhone 17 Pro takes group selfies that automatically expand and rotate as more people come into frame," says Apple. While the ad is focused on the iPhone 17 Pro and iPhone 17 Pro Max, the regular iPhone...
Apple Logo Zoomed

Tim Cook Teases Plans for Apple's Upcoming 50th Anniversary

Thursday February 5, 2026 12:54 pm PST by
Apple turns 50 this year, and its CEO Tim Cook has promised to celebrate the milestone. The big day falls on April 1, 2026. "I've been unusually reflective lately about Apple because we have been working on what do we do to mark this moment," Cook told employees today, according to Bloomberg's Mark Gurman. "When you really stop and pause and think about the last 50 years, it makes your heart ...
Finder Siri Feature

Why Apple's iOS 26.4 Siri Upgrade Will Be Bigger Than Originally Promised

Friday February 6, 2026 3:06 pm PST by
In the iOS 26.4 update that's coming this spring, Apple will introduce a new version of Siri that's going to overhaul how we interact with the personal assistant and what it's able to do. The iOS 26.4 version of Siri won't work like ChatGPT or Claude, but it will rely on large language models (LLMs) and has been updated from the ground up. Upgraded Architecture The next-generation...
iOS 26

iOS 26.3 and iOS 26.4 Will Add These New Features to Your iPhone

Tuesday February 3, 2026 7:47 am PST by
While the iOS 26.3 Release Candidate is now available ahead of a public release, the first iOS 26.4 beta is likely still at least a week away. Following beta testing, iOS 26.4 will likely be released to the general public in March or April. Below, we have recapped known or rumored iOS 26.3 and iOS 26.4 features so far. iOS 26.3 iPhone to Android Transfer Tool iOS 26.3 makes it easier...

Top Rated Comments

biggest father1 Avatar
144 months ago
Crap!!

This article just posted every single one of my passwords!
Score: 39 Votes (Like | Disagree)
farewelwilliams Avatar
144 months ago
totally related to Apple/Mac somehow.
Score: 18 Votes (Like | Disagree)
stiligFox Avatar
144 months ago
Damn, now I need to change the combination on my luggage!
Score: 17 Votes (Like | Disagree)
Shadow Runner Avatar
144 months ago
I see 1234567 isn't on there... my new password!
Score: 13 Votes (Like | Disagree)
Big-TDI-Guy Avatar
144 months ago
The combination is 1...2...3...4...5?

That's the kind of thing an idiot would have on his luggage!

Edit: stiligfox's Schwartz is slightly bigger than mine...
Score: 13 Votes (Like | Disagree)
ptb42 Avatar
144 months ago

Here are some examples of 3, 4, and 5 word phrases to give you an idea.
(In this variant, I put dashes between words and capitalize the first letter -- these are mainly to satisfy common password restrictions and don't change the strength of the password a lot.
XKCD: Password Strength (http://xkcd.com/936/)



It has been implemented here: https://xkpasswd.net/ (https://xkpasswd.net/)
Score: 9 Votes (Like | Disagree)