Analysis of 1B+ leaked credentials: “123456” accounts for one out of every 142 passwords, making it the most commonly reused password over the last five years
The ‘123456’ password was spotted 7 million times across a data trove of one billion leaked credentials … Tweets: @spencerchen Tweets: Spencer Chen / @spencerchen : Drop the “6”. Fool the hackers. https://twitter.com/...
Context & Ripple Effects
The scale of leaked credential corpora has been compounding for years: after Collection #1 surfaced with roughly 773M email addresses in January 2019, hackers followed weeks later by distributing Collections #2–5, some 25B records, nearly tripling it. This new analysis of a 1-billion-credential trove reads that accumulated data for what it says about user behavior, not just breach size.
The finding is blunt: '123456' appears about 7 million times — one out of every 142 passwords over the past five years — making trivially guessable reuse the norm, not the exception. It echoes earlier findings that huge dumps keep yielding the same weak secrets, including a later 3.28B-password dump containing 1.5M+ government-associated passwords.
First-order effects
- Every account still protected by '123456' is effectively pre-cracked for attackers holding these dumps, since the password tops the list an attacker tries first against any breached username.
- Security teams now have quantified evidence to enforce deny-lists of the most-reused passwords at signup and reset, rather than relying on complexity rules that don't stop sequential digits.
Second-order effects
- As long-tail dumps like the billion-record trove keep confirming reuse patterns, service providers face pressure to check new passwords against known-breached lists or push users toward alternatives like passkeys — because any password a user repeats across sites is only as strong as the weakest site holding it.
- Credential-stuffing economics improve for attackers as corpora grow: each new dump adds usernames whose owners demonstrably choose predictable passwords, lowering the cost per successful account takeover.
Third-order effects
- If one-in-142 reuse persists even as billions of records circulate publicly, the durable fix shifts from educating users to removing the password decision itself — industry momentum toward phishing-resistant, passwordless authentication becomes a structural response rather than a feature.
- The recurring mega-dump cycle — Collection #1, then Collections #2–5, then billion-scale analyses — suggests stolen credentials are now a persistent, aggregating commodity market, raising the case for regulators to treat password hygiene failures as a systemic risk rather than an individual user error.
The trend: Leaked-credential corpora are growing faster than user behavior improves, turning password reuse into a measurable commodity that accelerates the industry's shift toward passwordless authentication.