Worst Passwords of 2017 Include '123456' and 'Password' - MacRumors
Skip to Content

Worst Passwords of 2017 Include '123456' and 'Password'

SplashData today published its annual list of the worst passwords of the year, using data pulled from over five million passwords that were leaked across 2017 by hackers.

Despite many well-publicized major data leaks in 2016 and 2017, many people continue to use weak passwords that are easily guessed. "123456" and "Password," for example, were the two most popular passwords SplashData came across, as they have been for several years running.

worst passwords 2017
Other passwords in the top 10 of the worst passwords list included "12345678," "qwerty," "12345," "123456789," "letmein," "1234567," "football," and "iloveyou." "Monkey," "123123," and "starwars" also made the list this year, as new easily guessable passwords people have adopted. Passwords made up of a single word or consecutive number string are dangerous because they're so easy to guess.

"Unfortunately, while the newest episode may be a fantastic addition to the Star Wars franchise, 'starwars' is a dangerous password to use," said Morgan Slain, CEO of SplashData, Inc. "Hackers are using common terms from pop culture and sports to break into accounts online because they know many people are using those easy-to-remember words."

With data breaches from major companies so common, a strong password that consists of multiple random words or multiple numbers, letters, and characters is essential, and it's also important not to use the same password for more than one account.

Safari has built-in password generating features, and passwords can also be stored in the Keychain and accessed on all of your iOS and Mac devices. Password management apps like 1Password, LastPass, or SplashID can also make remembering and managing multiple passwords simple.

SplashData publishes its annual list to encourage people to use stronger passwords. This year, the company's data came primarily from North America and Western Europe, culled from data leaks. Yahoo data and data from adult websites was not included.

In 2017, there were several major data leaks from companies that included Verizon, Saks Fifth Avenue, Deloitte, and Uber, along with a huge Equifax breach that exposed the personal information of millions of people.

Popular Stories

iOS 26

iOS 26.4 Adds Two New Features to CarPlay

Tuesday March 24, 2026 1:55 pm PDT by
iOS 26.4 was released today, and it includes a couple of new features for CarPlay: an Ambient Music widget and support for voice-based chatbot apps. To update your iPhone 11 or newer to iOS 26.4, open the Settings app and tap on General → Software Update. CarPlay will automatically offer the new features so long as the iPhone connected to your vehicle is running iOS 26.4 or later....
Apple Business hero

Apple Unveils 'Apple Business' All-in-One Platform

Tuesday March 24, 2026 8:53 am PDT by
Apple today announced Apple Business, a new all-in-one platform that unifies device management, productivity tools, and customer outreach features. The service is designed to be a consolidated replacement for several of Apple's existing business-focused offerings, including Apple Business Essentials, Apple Business Manager, and Apple Business Connect. It provides organizations with a single...
AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4

Tuesday March 24, 2026 12:31 pm PDT by
Apple today released new firmware for the AirPods Pro 2, AirPods Pro 3, and the AirPods 4. The firmware has a version number of 8B39, up from 8B34 on the AirPods Pro 3, 8B28 on the AirPods Pro 2, and 8B21 on the AirPods 4. There is no word on what's included in the firmware, but Apple has a support document with limited notes. Most updates are limited to bug fixes and performance...

Top Rated Comments

108 months ago
Worst username/password combination...

Username: root
Password:
Score: 42 Votes (Like | Disagree)
djeeyore25 Avatar
108 months ago
"That's amazing! I've got the same combination on my luggage!"
Score: 16 Votes (Like | Disagree)
oneMadRssn Avatar
108 months ago
Hey guys, look what I discovered. If you try to post you password on this forum, it automatically replaced it with asterisks.

Look, this is my password: ********

Try it!
Score: 10 Votes (Like | Disagree)
Christoffee Avatar
108 months ago
These lists comes out every year.

Why don't the websites themselves incorporate this list into the mechanism that accepts your new password?

A lot of sites have, at minimum, a way to tell you if your password isn't long enough. And some also tell you that you need a number or uppercase letter.

Frankly... I'm not sure I'd wanna do business with a website that allows "123456" as a password. :p

Oh I'm still blaming the user overall... but I think the websites could help fix this terrible habit.
While I get what you're saying, rules imposed by websites infuriate me. I have a password system, that allows me to have long, unique passwords for everysite. It incorporates a number, a caps, and a sign. When i set my password and a website tells me that it must have at least two numbers I'm :mad:! The password is unique and 19 characters long! And you're telling me that I should use "monkey69".
Score: 5 Votes (Like | Disagree)
108 months ago
Score: 5 Votes (Like | Disagree)
SeminalSage Avatar
108 months ago
Hey guys, look what I discovered. If you try to post you password on this forum, it automatically replaced it with asterisks.

Look, this is my password: ********

Try it!
My password: ********

Holy cow, you were right!
Score: 5 Votes (Like | Disagree)