Updated: October 2026
Somewhere in your company, someone's password is on a list that attackers download for free. The list isn't secret, and neither is the way they use it. Here's what's on it this year, how attackers turn it into a login, and how to make sure nobody on your team can pick one of those passwords in the first place.
The Most Common Passwords Right Now
NordPass publishes the best-known yearly list. Its 2025 edition, the seventh, analysed passwords exposed in public data breaches and on dark web repositories between September 2024 and September 2025. The top of it looks like this.
| Rank | Password | Why it keeps winning |
|---|---|---|
| 1 | 12345 | The shortest thing a form will accept |
| 2 | 123456 | The same, when the form wants six characters |
| 3 | 12345678 | The same, when the form wants eight |
| 4 | 123456789 | One more digit, for luck |
| 5 | password | Literally what the box asked for |
| 6 | 1234567890 | The whole number row |
Five of the top six are the number row, stopped wherever the minimum length ran out. The sixth is the word the field was labelled with. Further down, the list picks up pop culture: "skibidi" made the global top ten.
None of this means people are careless. It means the easiest password that passes the rules is the one that gets used. When a system only asks for eight characters, 12345678 passes. Fix the rule, and the list changes.
Why the List Matters to a Company
Attackers don't guess at random. They start with the same lists you're reading about, because those lists work. The Verizon 2025 DBIR found stolen or abused credentials were the first step in 22% of breaches.
For a company, one weak password rarely stays one weak password. The account it opens has email, files and often admin access somewhere. That's the door, and the most common passwords are the keys attackers try first.
What Is a Brute Force Attack?
A brute force attack is guessing a password by trying many options against one account until something works. The classic version runs through a wordlist, starting with the most common passwords.
Brute force comes in four forms. Simple guessing tries every combination of characters, which only works on short passwords. A dictionary attack runs through wordlists of leaked and common passwords, like the list above. A hybrid attack takes a dictionary word and adds the usual tweaks: a capital letter, a year, an exclamation mark. Offline cracking skips the login page altogether. The attacker steals a file of password hashes and guesses against it on their own hardware, where no lockout applies.
Online guessing is the easiest to stop. Lock the account after a handful of failures and the guessing stalls. Microsoft's account lockout guidance points to 10 failed sign-ins as a starting threshold, taken from its Windows security baselines. Go much lower and an attacker can lock every account on purpose, which turns the defense into a denial of service.
Lockouts only guard the sign-in page, and attackers adapted. Against live sign-ins, they moved to two quieter methods that don't trip lockouts.
Password Spraying and Credential Stuffing
Password spraying flips brute force around. Instead of many passwords against one account, it tries a few of the most common passwords against every account in the company. Each account sees one or two failures, well under any lockout, and somebody's Spring2025! eventually works. Microsoft's own Entra documentation describes it the same way: attackers try "only a few of the known weakest passwords" against each account to stay under detection thresholds.
It works on big targets too. In January 2024, Microsoft disclosed that the Midnight Blizzard group got in with a password spray against "a legacy, non-production test tenant account that did not have multifactor authentication (MFA) enabled," per its security blog. One forgotten account, one common password, no second factor.
This r/sysadmin thread picked the story apart when it broke, including the exec complaints that MFA is "too annoying".
Credential stuffing needs no guessing at all. Attackers take email and password pairs leaked from one site and try them on others. If an employee reused their shopping password for work email, the attacker walks straight in.
Jeff Crume from IBM Technology walks through guessing, spraying and stuffing side by side, and where MFA and passkeys stop each one.
Block the List With a Banned-Password List
The fix for a list-based attack is a list-based defence. Microsoft Entra Password Protection checks every new password against banned terms when a user sets or resets it.
It has two layers. The global banned list is built from Microsoft's own sign-in telemetry, applies to every tenant automatically, and can't be switched off. The custom list is yours: up to 1,000 terms, meant for your brand, products, office locations and internal slang. Microsoft's advice is to ban base terms only, like "Contoso" or "London", and let the matching catch the variants.
The matching is what makes it work. Entra lowercases the password and swaps common substitutions back, so 0 becomes o, @ becomes a and $ becomes s. It then allows a difference of one character, checks for the user's own name, and scores what's left. Each banned term counts one point, each other character counts one, and the password needs five points to pass. By Microsoft's own example, C0ntos0Blank12 scores four and fails, while ContoS0Bl@nkf9! scores five and passes.
The global list is included with Entra ID Free for cloud-only users. The custom list, and coverage for users synced from on-premises Active Directory, needs P1 or P2. On-premises domain controllers get the same checks through a small agent.
Two details matter at rollout. The check runs when a password is changed or reset, so existing passwords stay until their next change. And the on-premises agent can run in audit mode first, logging which passwords it would have rejected without blocking anyone, which shows you the size of the problem before anyone gets a surprise error.
One decision trips teams up: whether to publish the custom list so users know what's banned. This r/sysadmin thread is a good read before that meeting, and the top replies are firmly against it.
What NIST Says Now
The US standard for password rules, NIST SP 800-63B-4, went final in July 2025. It undoes a lot of the password advice IT teams grew up with.
A password used on its own must be at least 15 characters. A password used alongside MFA can be as short as eight. Systems should allow at least 64 characters, so long passphrases fit. Composition rules, the "one uppercase, one number, one symbol" kind, are banned outright. So are forced periodic changes, which is what gave the world Summer2025! followed by Autumn2025!.
What NIST does require is checking every new password against a blocklist of common and breached passwords. That's exactly the job a banned-password list does. Password hints and security questions like "name of your first pet" are out too.
For company staff, the practical version is short: a long phrase you can remember beats a short string of symbols you can't. For IT, it's permission to drop the 90-day rotation and spend the effort on the blocklist and MFA instead. If your team needs somewhere to keep all those long passwords, our password manager roundup compares the options.
Passwords Are the Floor: Add MFA and Passkeys
A banned-password list stops the worst passwords. It doesn't stop a good password that was phished or reused. MFA covers that gap, and passkeys go further by removing the password from the login entirely.
The order that works: turn on the banned-password list, require MFA everywhere, and keep admin rights tight so a stolen login opens as little as possible. Our guide to endpoint privilege management covers that last step.
The most common passwords will change next year. 123456 probably won't. Block it once, and it stops being your problem.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
