Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Somewhere in your company, someone's password is on a list that attackers download for free. The list isn't secret, and neither is the way they use it. Here's what's on it this year, how attackers turn it into a login, and how to make sure nobody on your team can pick one of those passwords in the first place.

The Most Common Passwords Right Now

NordPass publishes the best-known yearly list. Its 2025 edition, the seventh, analysed passwords exposed in public data breaches and on dark web repositories between September 2024 and September 2025. The top of it looks like this.

RankPasswordWhy it keeps winning
112345The shortest thing a form will accept
2123456The same, when the form wants six characters
312345678The same, when the form wants eight
4123456789One more digit, for luck
5passwordLiterally what the box asked for
61234567890The whole number row

Five of the top six are the number row, stopped wherever the minimum length ran out. The sixth is the word the field was labelled with. Further down, the list picks up pop culture: "skibidi" made the global top ten.

None of this means people are careless. It means the easiest password that passes the rules is the one that gets used. When a system only asks for eight characters, 12345678 passes. Fix the rule, and the list changes.

Why the List Matters to a Company

Attackers don't guess at random. They start with the same lists you're reading about, because those lists work. The Verizon 2025 DBIR found stolen or abused credentials were the first step in 22% of breaches.

For a company, one weak password rarely stays one weak password. The account it opens has email, files and often admin access somewhere. That's the door, and the most common passwords are the keys attackers try first.

What Is a Brute Force Attack?

A brute force attack is guessing a password by trying many options against one account until something works. The classic version runs through a wordlist, starting with the most common passwords.

Brute force comes in four forms. Simple guessing tries every combination of characters, which only works on short passwords. A dictionary attack runs through wordlists of leaked and common passwords, like the list above. A hybrid attack takes a dictionary word and adds the usual tweaks: a capital letter, a year, an exclamation mark. Offline cracking skips the login page altogether. The attacker steals a file of password hashes and guesses against it on their own hardware, where no lockout applies.

Online guessing is the easiest to stop. Lock the account after a handful of failures and the guessing stalls. Microsoft's account lockout guidance points to 10 failed sign-ins as a starting threshold, taken from its Windows security baselines. Go much lower and an attacker can lock every account on purpose, which turns the defense into a denial of service.

Lockouts only guard the sign-in page, and attackers adapted. Against live sign-ins, they moved to two quieter methods that don't trip lockouts.

Password Spraying and Credential Stuffing

Password spraying flips brute force around. Instead of many passwords against one account, it tries a few of the most common passwords against every account in the company. Each account sees one or two failures, well under any lockout, and somebody's Spring2025! eventually works. Microsoft's own Entra documentation describes it the same way: attackers try "only a few of the known weakest passwords" against each account to stay under detection thresholds.

It works on big targets too. In January 2024, Microsoft disclosed that the Midnight Blizzard group got in with a password spray against "a legacy, non-production test tenant account that did not have multifactor authentication (MFA) enabled," per its security blog. One forgotten account, one common password, no second factor.

This r/sysadmin thread picked the story apart when it broke, including the exec complaints that MFA is "too annoying".

Credential stuffing needs no guessing at all. Attackers take email and password pairs leaked from one site and try them on others. If an employee reused their shopping password for work email, the attacker walks straight in.

Jeff Crume from IBM Technology walks through guessing, spraying and stuffing side by side, and where MFA and passkeys stop each one.

Block the List With a Banned-Password List

The fix for a list-based attack is a list-based defence. Microsoft Entra Password Protection checks every new password against banned terms when a user sets or resets it.

It has two layers. The global banned list is built from Microsoft's own sign-in telemetry, applies to every tenant automatically, and can't be switched off. The custom list is yours: up to 1,000 terms, meant for your brand, products, office locations and internal slang. Microsoft's advice is to ban base terms only, like "Contoso" or "London", and let the matching catch the variants.

The matching is what makes it work. Entra lowercases the password and swaps common substitutions back, so 0 becomes o, @ becomes a and $ becomes s. It then allows a difference of one character, checks for the user's own name, and scores what's left. Each banned term counts one point, each other character counts one, and the password needs five points to pass. By Microsoft's own example, C0ntos0Blank12 scores four and fails, while ContoS0Bl@nkf9! scores five and passes.

The global list is included with Entra ID Free for cloud-only users. The custom list, and coverage for users synced from on-premises Active Directory, needs P1 or P2. On-premises domain controllers get the same checks through a small agent.

Two details matter at rollout. The check runs when a password is changed or reset, so existing passwords stay until their next change. And the on-premises agent can run in audit mode first, logging which passwords it would have rejected without blocking anyone, which shows you the size of the problem before anyone gets a surprise error.

One decision trips teams up: whether to publish the custom list so users know what's banned. This r/sysadmin thread is a good read before that meeting, and the top replies are firmly against it.

What NIST Says Now

The US standard for password rules, NIST SP 800-63B-4, went final in July 2025. It undoes a lot of the password advice IT teams grew up with.

A password used on its own must be at least 15 characters. A password used alongside MFA can be as short as eight. Systems should allow at least 64 characters, so long passphrases fit. Composition rules, the "one uppercase, one number, one symbol" kind, are banned outright. So are forced periodic changes, which is what gave the world Summer2025! followed by Autumn2025!.

What NIST does require is checking every new password against a blocklist of common and breached passwords. That's exactly the job a banned-password list does. Password hints and security questions like "name of your first pet" are out too.

For company staff, the practical version is short: a long phrase you can remember beats a short string of symbols you can't. For IT, it's permission to drop the 90-day rotation and spend the effort on the blocklist and MFA instead. If your team needs somewhere to keep all those long passwords, our password manager roundup compares the options.

Passwords Are the Floor: Add MFA and Passkeys

A banned-password list stops the worst passwords. It doesn't stop a good password that was phished or reused. MFA covers that gap, and passkeys go further by removing the password from the login entirely.

The order that works: turn on the banned-password list, require MFA everywhere, and keep admin rights tight so a stolen login opens as little as possible. Our guide to endpoint privilege management covers that last step.

The most common passwords will change next year. 123456 probably won't. Block it once, and it stops being your problem.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Most Common Passwords

In NordPass's 2025 list, built from breach and dark web data collected between September 2024 and September 2025, the most common password was 12345, followed by 123456 and 12345678. Five of the top six were digits from the keyboard number row, and the sixth was the word password.
No. MFA stops a stolen or guessed password from being enough on its own, but a common password still makes the first step easy, and some logins and legacy protocols skip MFA. Use a long, uncommon password and MFA together.
Only when there's a reason, such as a suspected breach or a password found in a leak. NIST SP 800-63B-4, final in July 2025, says systems shall not force periodic password changes, because scheduled rotation pushes people to predictable variations like Summer2025! and Autumn2025!.
Length and uniqueness. NIST SP 800-63B-4 asks for at least 15 characters when a password is the only factor, allows at least 64, drops complexity rules, and requires checking new passwords against lists of common and breached passwords. A long passphrase used nowhere else is stronger than a short string of symbols.

About OpenFrame

In the cloud, on US soil. Your data stays stateside.
OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.