Special Report
The Most Used Passwords in America and How Long They Take to Crack
Published:
Harvard University’s Information Security group says a good password for an online account has at least 10 characters with a combination of English uppercase and lowercase letters and numbers and symbols, like # or %.
The group suggests starting with a word you can remember and then modify it to meet these requirements. For example, the word “strawberry” could be modified into leetspeak – the convention that replaces letters with numbers and/or symbols – to spell out “$tRAWb3rry” and the result would be a fairly secure password. This type of password might not be the strongest, but it’s secure enough for your Facebook page or bank account.
According to NordPass, a proprietary password manager, many Americans are still using unmodified lowercase words or simple numeric combinations to verify their identities, resulting in common passwords that are widely shared and easy for software programs to break in as little as a second.
To compile a list of the most common passwords in the U.S. in 2022, 24/7 Tempo reviewed a recent study of passwords worldwide by NordPass, which worked with independent researchers specializing in cybersecurity incidents in 30 countries. (These are the countries with the most leaked passwords.)
The most frequently used passwords for U.S.-based online accounts include, “guest,” “monkey,” and, yes, “password” – most of which could be guessed almost instantly by anyone with rudimentary knowledge of cybersecurity and the right software. (You might be particularly vulnerable if you live in one of the states with the most identity theft.)
Apparently, there are a lot of sports fans among these careless American netizens, because other common easy-to-crack passwords used in this country include “football,” “soccer,” “baseball,” and the oddly specific “jordan23,” referring to basketball legend Michael Jordan. By the way, adding Jordan’s jersey number to the end of his last name doesn’t slow down password-cracking tools a bit.
Neither does using a string of numbers. The numeric password “123456789” or the four other variants that rank among the most common passwords in America, is not much safer than if you used just one number. Modern computational power surpasses your ability to imagine any numeric combination that would fit in the password window of a typical login page.
Click here to see the most used passwords in America and how long they take to crack
Even many seemingly esoteric passwords can be cracked. The 20th most common password in America, according to NordPass is “g_czechout.” The underscore and the unconventional spelling make the password harder to crack – it takes 12 days instead of just seconds or minutes. But this password would be more secure by orders of computational magnitude if you simply added numbers, uppercase letters, and a symbol to the combination.
20. g_czechout
> Time to crack: 12 days
> Americans with that password: 4,482
[in-text-ad]
19. shadow
> Time to crack: Less than 1 second
> Americans with that password: 4,483
18. monkey
> Time to crack: Less than 1 second
> Americans with that password: 4,694
17. iloveyou
> Time to crack: Less than 1 second
> Americans with that password: 4,816
[in-text-ad-2]
16. jordan23
> Time to crack: Less than 1 second
> Americans with that password: 4,979
15. soccer
> Time to crack: Less than 1 second
> Americans with that password: 5,062
[in-text-ad]
14. unknown
> Time to crack: 17 minutes
> Americans with that password: 5,833
13. football
> Time to crack: Less than 1 second
> Americans with that password: 6,450
12. baseball
> Time to crack: Less than 1 second
> Americans with that password: 6,574
[in-text-ad-2]
11. qwerty
> Time to crack: Less than 1 second
> Americans with that password: 7,503
10. 12345678
> Time to crack: Less than 1 second
> Americans with that password: 8,671
[in-text-ad]
9. abc123
> Time to crack: Less than 1 second
> Americans with that password: 9,604
8. 1234
> Time to crack: Less than 1 second
> Americans with that password: 9,952
7. Password1
> Time to crack: Less than 1 second
> Americans with that password: 11,315
[in-text-ad-2]
6. 123456789
> Time to crack: Less than 1 second
> Americans with that password: 13,945
5. a1b2c3
> Time to crack: Less than 1 second
> Americans with that password: 15,702
[in-text-ad]
4. 12345
> Time to crack: Less than 1 second
> Americans with that password: 31,675
3. password
> Time to crack: Less than 1 second
> Americans with that password: 74,533
2. 123456
> Time to crack: Less than 1 second
> Americans with that password: 109,322
[in-text-ad-2]
1. guest
> Time to crack: 10 seconds
> Americans with that password: 127,861
Start by taking a quick retirement quiz from SmartAsset that will match you with up to 3 financial advisors that serve your area and beyond in 5 minutes, or less.
Each advisor has been vetted by SmartAsset and is held to a fiduciary standard to act in your best interests.
Here’s how it works:
1. Answer SmartAsset advisor match quiz
2. Review your pre-screened matches at your leisure. Check out the advisors’ profiles.
3. Speak with advisors at no cost to you. Have an introductory call on the phone or introduction in person and choose whom to work with in the future
Get started right here.
Thank you for reading! Have some feedback for us?
Contact the 24/7 Wall St. editorial team.