Worst Passwords of 2017 Include '123456' and 'Password'

SplashData today published its annual list of the worst passwords of the year, using data pulled from over five million passwords that were leaked across 2017 by hackers.

Despite many well-publicized major data leaks in 2016 and 2017, many people continue to use weak passwords that are easily guessed. "123456" and "Password," for example, were the two most popular passwords SplashData came across, as they have been for several years running.

worst passwords 2017
Other passwords in the top 10 of the worst passwords list included "12345678," "qwerty," "12345," "123456789," "letmein," "1234567," "football," and "iloveyou." "Monkey," "123123," and "starwars" also made the list this year, as new easily guessable passwords people have adopted. Passwords made up of a single word or consecutive number string are dangerous because they're so easy to guess.

"Unfortunately, while the newest episode may be a fantastic addition to the Star Wars franchise, 'starwars' is a dangerous password to use," said Morgan Slain, CEO of SplashData, Inc. "Hackers are using common terms from pop culture and sports to break into accounts online because they know many people are using those easy-to-remember words."

With data breaches from major companies so common, a strong password that consists of multiple random words or multiple numbers, letters, and characters is essential, and it's also important not to use the same password for more than one account.

Safari has built-in password generating features, and passwords can also be stored in the Keychain and accessed on all of your iOS and Mac devices. Password management apps like 1Password, LastPass, or SplashID can also make remembering and managing multiple passwords simple.

SplashData publishes its annual list to encourage people to use stronger passwords. This year, the company's data came primarily from North America and Western Europe, culled from data leaks. Yahoo data and data from adult websites was not included.

In 2017, there were several major data leaks from companies that included Verizon, Saks Fifth Avenue, Deloitte, and Uber, along with a huge Equifax breach that exposed the personal information of millions of people.

Popular Stories

wwdc sans text feature

Apple Rumored to Announce New Product on February 19

Thursday February 5, 2026 12:22 pm PST by
Apple plans to announce the iPhone 17e on Thursday, February 19, according to Macwelt, the German equivalent of Macworld. The report, citing industry sources, is available in English on Macworld. Apple announced the iPhone 16e on Wednesday, February 19 last year, so the iPhone 17e would be unveiled exactly one year later if this rumor is accurate. It is quite uncommon for Apple to unveil...
Apple Logo Zoomed

Tim Cook Teases Plans for Apple's Upcoming 50th Anniversary

Thursday February 5, 2026 12:54 pm PST by
Apple turns 50 this year, and its CEO Tim Cook has promised to celebrate the milestone. The big day falls on April 1, 2026. "I've been unusually reflective lately about Apple because we have been working on what do we do to mark this moment," Cook told employees today, according to Bloomberg's Mark Gurman. "When you really stop and pause and think about the last 50 years, it makes your heart ...
maxresdefault

Apple Shows Off a Key Reason to Upgrade to the iPhone 17

Saturday February 7, 2026 9:26 am PST by
Apple today shared an ad that shows how the upgraded Center Stage front camera on the latest iPhones improves the process of taking a group selfie. "Watch how the new front facing camera on iPhone 17 Pro takes group selfies that automatically expand and rotate as more people come into frame," says Apple. While the ad is focused on the iPhone 17 Pro and iPhone 17 Pro Max, the regular iPhone...
Finder Siri Feature

Why Apple's iOS 26.4 Siri Upgrade Will Be Bigger Than Originally Promised

Friday February 6, 2026 3:06 pm PST by
In the iOS 26.4 update that's coming this spring, Apple will introduce a new version of Siri that's going to overhaul how we interact with the personal assistant and what it's able to do. The iOS 26.4 version of Siri won't work like ChatGPT or Claude, but it will rely on large language models (LLMs) and has been updated from the ground up. Upgraded Architecture The next-generation...
iOS 26

iOS 26.3 and iOS 26.4 Will Add These New Features to Your iPhone

Tuesday February 3, 2026 7:47 am PST by
While the iOS 26.3 Release Candidate is now available ahead of a public release, the first iOS 26.4 beta is likely still at least a week away. Following beta testing, iOS 26.4 will likely be released to the general public in March or April. Below, we have recapped known or rumored iOS 26.3 and iOS 26.4 features so far. iOS 26.3 iPhone to Android Transfer Tool iOS 26.3 makes it easier...

Top Rated Comments

infinitedreams Avatar
106 months ago
Worst username/password combination...

Username: root
Password:
Score: 42 Votes (Like | Disagree)
djeeyore25 Avatar
106 months ago
"That's amazing! I've got the same combination on my luggage!"
Score: 16 Votes (Like | Disagree)
oneMadRssn Avatar
106 months ago
Hey guys, look what I discovered. If you try to post you password on this forum, it automatically replaced it with asterisks.

Look, this is my password: ********

Try it!
Score: 10 Votes (Like | Disagree)
potatis Avatar
106 months ago
Score: 5 Votes (Like | Disagree)
Christoffee Avatar
106 months ago
These lists comes out every year.

Why don't the websites themselves incorporate this list into the mechanism that accepts your new password?

A lot of sites have, at minimum, a way to tell you if your password isn't long enough. And some also tell you that you need a number or uppercase letter.

Frankly... I'm not sure I'd wanna do business with a website that allows "123456" as a password. :p

Oh I'm still blaming the user overall... but I think the websites could help fix this terrible habit.
While I get what you're saying, rules imposed by websites infuriate me. I have a password system, that allows me to have long, unique passwords for everysite. It incorporates a number, a caps, and a sign. When i set my password and a website tells me that it must have at least two numbers I'm :mad:! The password is unique and 19 characters long! And you're telling me that I should use "monkey69".
Score: 5 Votes (Like | Disagree)
SeminalSage Avatar
106 months ago
Hey guys, look what I discovered. If you try to post you password on this forum, it automatically replaced it with asterisks.

Look, this is my password: ********

Try it!
My password: ********

Holy cow, you were right!
Score: 5 Votes (Like | Disagree)