List of the most common passwords
Wikimedia list article

This is a list of the most common passwords, discovered in various data breaches. Common passwords are generally not recommended on account of low password strength.
List
NordPass
In 2025, NordPass, a password manager, released its seventh annual list of the 200 most common passwords. The top twenty most frequently used passwords are:
SplashData
The Worst Passwords List is an annual list of the 25 most common passwords from each year as produced by internet security firm SplashData. Since 2011, the firm has published the list based on data examined from millions of passwords leaked in data breaches, mostly in North America and Western Europe, over each year. In the 2016 edition, the 25 most common passwords made up more than 10% of the surveyed passwords, with the most common password of 2016, "123456", making up 4%.
Keeper
Password manager Keeper compiled its own list of the 25 most common passwords in 2016, from 25 million passwords leaked in data breaches that year.
National Cyber Security Centre
The National Cyber Security Centre (NCSC) hosts a list, compiled by Troy Hunt of Have I Been Pwned?, of the top 100 thousand passwords leaked in data breaches as of 2019.
Huntress
The most common passwords of 2026, according to Huntress.
The public source identifies “List of the most common passwords” as wikimedia list article. This brief keeps that definition visible, then builds a research path around List, most and common.
Why this record matters
A short description can identify a subject without explaining its stakes. For “List of the most common passwords”, the useful work is to connect “wikimedia list article” to the records capable of establishing context and consequence.
Named sources, stable identifiers and responsible institutions provide the strongest route from overview to verifiable evidence. The source revision retrieved here is dated Sep 5, 2026. The linked authority identifier is Q30324928. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2025, 2011, 2016 and 2019.
The absence of detail may reflect summary conventions rather than a lack of surviving documentation. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “List of the most common passwords”, its source revision and the description used here.
- Expand the search: follow List of the most common passwords primary sources, List of the most common passwords archive and List research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “List of the most common passwords”?
- Which cited source is closest to the event, object or claim?
- Which institution is responsible for the underlying evidence?
Search terms from this dossier
This entry incorporates text from “List of the most common passwords” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.