These are the 25 worst passwords of 2019

LOOK ON THE bright side! There’s one good thing that comes out of all those website breaches every year: Security researchers get to comb through all the lists of usernames and passwords to remind us just how bad most of our passwords are. We may be well into 2020, but it’s not too late to heed the lessons password-management company SplashData conveys through its list of the 25 worst passwords of 2019.

SplashData’s annual roundup of the worst passwords of 2019 is based on more than 2 million passwords that leaked online during that year. One trend the company found in 2019 is that while users are coming up with longer passwords (that’s good), they are simple and not random (that’s bad). Two examples the company points to are 1234567890 and qwertyuiop. One just uses every number key and the other uses the top row of keys on a standard QWERTY keyboard.

More common password faux pas include using basic numerical passwords and sports terms. Star Wars: The Force Awakens was big news in 2019, and it seems many people went with Star Wars–themed passwords such as starwars, solo, and princess. Star Wars fans may be Jedis in other areas, but they’re still Padawans when it comes to passwords.

One trend the company found in 2019 is that while users are coming up with longer passwords (that’s good), they are simple and not random (that’s bad).

Here’s Splashdata’s complete list of the 25 worst passwords for 2019, with their ranking from 2018 in brackets:

1. 123456 (Unchanged)

2. password (Unchanged)

3. 12345678 (Up 1)

4. qwerty (Up 1)

5. 12345 (Down 2)

6. 123456789 (Unchanged)

7. football (Up 3)

8. 1234 (Down 1)

9. 1234567 (Up 2)

10. baseball (Down 2)

11. welcome (New)

12. 1234567890 (New)

13. abc123 (Up 1)

14. 111111 (Up 1)

15. 1qaz2wsx (New)

16. dragon (Down 7)

17. master (Up 2)

18. monkey (Down 6)

19. letmein (Down 6)

20. login (New)

21. princess (New)

22. qwertyuiop (New)

23. solo (New)

24. passw0rd (New)

25. starwars (New)

Save yourself

There’s no doubt about it, managing passwords is a pain, but they’re the best security measure available right now. Tech companies are working to change that, but at the moment there’s no getting around the need for good, strong passwords.

The best thing to do is to create long, random passwords that are hard to guess. Your passwords should use a combination of letters (including different cases), numbers, and symbols if possible. Also make sure you use a unique password for every major account you have, including banking, email, Paypal, social networks, and any website that has your credit card data, such as Amazon.

If you have trouble remembering those new passwords, then use a password manager such as KeePass, LastPass, Dashlane, or SplashID.

You should also use multifactor authentication whenever it’s offered to keep your accounts extra safe. That way if you ever lose control of your password, malicious hackers won’t be able to break into your account without the numeric code generated on your smartphone. Most major services support multifactor authentication, including Amazon, Facebook, Gmail, Microsoft, and Twitter.

Keeping your accounts secure isn’t simple, but if you stick to the basics you can minimize the complexity—and adhering to best practices will save you from headaches should your account credentials end up in the hands of hackers.