Back The 10 most used passwords are deciphered in less than a second

2026 / 05 / 07
ZIURek ohartarazten du: Pasahitz ahul batek atea ireki diezaioke zure bizitza digital osoari segundo batzuetan; zure segurtasuna indartzea da zibererasoen aurkako lehen defentsa lerroa.

The 10 most used passwords are deciphered in less than a second

ZIUR warns: “A weak password can open the door to your entire digital life in a matter of seconds; strengthening its security is the first line of defense against cyberattacks”.

ZIUR, the Cybersecurity Center of the Gipuzkoa Provincial Council, warns that the most commonly used passwords can be cracked almost instantly, leaving millions of personal and professional accounts vulnerable. To mark World Password Day, commemorated today, ZIUR points out that the 10 most popular passwords can be hacked in less than one second.

According to the most recent 2025 reports and 2026 projections from specialized companies like NordPass and ESET, the 10 most compromised passwords are: admin; 123456; 12345678; 123456789; 12345; password; 1234567890; 1111; Contraseña; and, finally, qwerty123.

This data demonstrates that the use of weak passwords remains one of the main entry points for cybercriminals. In this context, ZIUR is calling for improved digital habits and reminding users of a series of basic recommendations for protecting their information.

Among the main guidelines, they emphasize the need to use a different password for each important service, especially in critical areas such as email or online banking. They also recommend opting for long passwords instead of complex ones, choosing phrases that are easy to remember but difficult to guess.

Using password managers is another key practice highlighted by ZIUR, as they allow users to securely store multiple passwords without having to memorize them. Bitwarden (free), 1Password (paid), or the password manager on your mobile phone are the most recommended and user-friendly options. In addition, they recommend enabling two-step verification (2FA), considered one of the most effective tools for blocking unauthorized access attempts, even in cases of password theft.

ZIUR also warns about common mistakes to avoid, such as using obvious personal information, common passwords, or sharing credentials through insecure channels. “It’s not necessary to change passwords periodically for no reason, but it is essential to do so at the first sign of any suspected compromise or after a security breach. A long, unique password for each important site, stored in a password manager, and with two-factor authentication enabled for email and banking, for example, protects the average user against the vast majority of common threats,” insists ZIUR’s director, María Penilla.

Changing your password at the slightest suspicion that it may be known by someone, when the website you are using it on suffers a security breach, or after prolonged use of the same password on sensitive sites, are, finally, the recommendations offered by ZIUR to determine when it’s time to change your password.