By J. Mesa
Attackers don’t break into most accounts. They log in. They take a list of the passwords people use most, try each one against your email or your bank, and move on to the next person. If your password sits on that list, the attack takes seconds and needs no skill.
This post covers the passwords attackers try first, why they work, and the stronger habit I recommend to every client: the passphrase.
What are the most common passwords?
NordPass publishes a yearly study built from millions of passwords exposed in data breaches. In its 2025 report, these five led the United States list:
- admin
- password
- 123456
- 12345678
- 123456789
The global list looks much the same, with 123456 in first place. Older favorites such as qwerty, 111111, and abc123 still rank high every year. The names change order. The pattern holds: short, predictable, and typed by millions of people.
Why do hackers try these passwords first?
Attackers don’t type guesses by hand. They run software that tests thousands of passwords per second, and that software starts with wordlists built from past breaches. Three common attacks rely on those lists:
- Dictionary attack. The tool tries every word and common password on a list against one account.
- Password spraying. The attacker tries one common password, such as Password1, against every employee in a company. One match gives them a way in.
- Credential stuffing. The attacker takes email and password pairs leaked from one site and tries them on other sites. This works because people reuse passwords.
A password from the top five fails all three attacks on the first try.
Is adding a number or symbol enough?
No. Attackers know the tricks. Their tools swap a for @, add 1 or ! to the end, and capitalize the first letter. Password1! sits at number 16 on the 2025 list.
A short password full of symbols, such as x7g9@k2!, is also weak. Eight characters is short enough that cracking hardware can work through every combination when a site stores passwords poorly. It is also hard for you to remember, so you write it down or reuse it.
Length beats complexity. Each character you add multiplies the work an attacker has to do.
How long should a password be?
The National Institute of Standards and Technology (NIST) writes the password guidance that most US security standards follow. Its current guidance, SP 800-63B, calls for at least 15 characters on an account protected by a password alone. It also tells organizations to stop requiring mixed character types and to accept long passwords of at least 64 characters.
Fifteen random characters are hard to remember. Fifteen characters of words are easy. That is the case for a passphrase.
What is a passphrase, and is it safer than a password?
A passphrase is a string of several unrelated words. It runs longer than a traditional password, so it resists guessing and brute-force attacks, and you can remember it because you know the words.
Compare the two. The password x7g9@k2! has 8 characters. The passphrase kadu tasi ayuyu babui has 21.
That example uses words from Chamorro, my own language. Words from a language other than English make a passphrase stronger, because many attacker wordlists focus on English and on passwords leaked from English-language sites. The phrase means something to me and reads as gibberish to a cracking tool.
How do I create a strong passphrase?
- Pick four or more words that have no connection to each other.
- Avoid quotes, song lyrics, and famous examples. If a phrase appears in a book or a movie, it appears in a wordlist.
- Mix in a word from another language, a place only you know, or an invented word.
- Aim for 15 characters or more.
- Use a different passphrase for every important account.
A personal touch helps you remember it. Keep personal facts out of it. Your pet’s name, your birth year, and your street all show up on your social media, and attackers check there first.
Do I need to change my password every 90 days?
No. NIST now tells organizations to stop forcing password changes on a schedule. Forced changes push people toward weak patterns, such as Summer2025 turning into Fall2025. Change a password when you have a reason: a breach notice, a phishing link you clicked, or a shared login after someone leaves the company.
How do I know if my password was exposed?
Search your email address at haveibeenpwned.com, a free service that tracks breached accounts. Many password managers and browsers run the same check and warn you about exposed logins. If a password shows up in a breach, change it on that site and on every site where you reused it.
How do I remember a different passphrase for every account?
You don’t. Use a password manager. You remember one strong passphrase, and the manager creates and stores a unique password for each account.
Then turn on multi-factor authentication (MFA) wherever a site offers it. With MFA, a stolen password alone does not open the account.
What should a small business do about passwords?
- Set a minimum length of 15 characters and drop the forced 90-day change.
- Block the common passwords listed above. Most identity systems, including Microsoft 365, can do this.
- Give every employee a password manager.
- Require MFA on email, banking, and remote access.
- Train your team to spot phishing. A passphrase does not help once someone types it into a fake login page.
What makes a password weak?
A password is weak when an attacker can predict it. Short length, common words, keyboard patterns such as qwerty, repeated characters, and personal details all make a password easy to predict. Reuse makes a strong password weak too, because one breached site exposes every account that shares it.
Your next step
Check your own accounts against the list in this post today. If you run a business and want help writing a password policy or training your team, contact Cerberus Cybersecurity. We put people first, and passwords are a people problem.
A strong passphrase is your first line of defense. Treat it that way.

Leave a Reply