
SCARS Institute’s Encyclopedia of Scams™ Published Continuously for 25 Years

Most Hacked Passwords Revealed
Exposed as UK cyber survey exposes gaps in online security
The U.K. National Cyber Security Centre’s (NCSC) global hacked password risk list
- Breach analysis finds 23.2 million victim accounts worldwide used only ‘123456’ as a password
- Global password risk list published to disclose passwords already known to hackers
- SCARS and the NCSC urge using 3 random words as passwords
Why is password reuse a problem?
Because they easily turn into hacked passwords!
Password reuse is still a major risk for individuals and companies. The password ‘123456’ has been found 23 million times in the breaches that was collected. You might think that choosing a more complex password such as ‘oreocookie’ is better, but even that has been seen over 3,000 times.
Attackers commonly use lists like those of easily hacked passwords when attempting to breach a perimeter, take over an account, or when trying to move within a network to potentially less well-defended systems. It’s especially common in networks where there’s a corporate component. In such deployments, attackers have been able to breach the corporate network and move laterally to the internal network due to poor network segmentation, where a single weak point (such as a password from one of these lists on a box in a DMZ) has enabled traversal. In the first occurrence of the TRITON/TRISIS malware, the attacker breached the external perimeter VPN and then pivoted internally using RDP due to poor segmentation.
But they also do exactly the same things to take over social media accounts, access online banking, or many other accounts of high value to cybercriminals.
More than half of the people online do not use a strong, separate password for their main email account! Email is one of the most valuable accounts users have!
They were all easy for hackers, bots, and automated password breakers to guess and apply to gain access to important accounts.
Upgrade your passwords NOW! Learn more about passwords here.
-/ 30 /-
What do you think about this?
Please share your thoughts in a comment below!
Table of Contents
To Understand All Scams
Read This
The SCARS Institute Relationship Scams Formula Checklist
This is the Formula that all Relationship Scams Follow
Recent Comments
On Other Articles
- Barbara on SCARS Institute – Romance Scam Simulator: “Fantastic! I have to go to bed, but I’ll do some more tomorrow. I picked an easy scenario tonight, but…” Oct 9, 18:01
- on United States – Federal Bureau of Investigations [FBI]: “It is only that way because of the shame you feel. The reality is that it was not your fault.…” Sep 30, 15:36
- on United States – Federal Bureau of Investigations [FBI]: “yhisis humiliating experience e and isembarassassing to to own up to peolealreadyassume u are not to bright because Arnold and…” Sep 30, 12:28
- on United States – Federal Bureau of Investigations [FBI]: “should be better known by public live in assisiwdlivi g apartment many manyinstancresof Romance scams here ano.us ederly l” Sep 30, 12:24
- on Is It A Scam? Phone Scam Diagnostic – v1: “I tried the this test Is it a phone scam? Mine was. I think this is a helpful tool to…” Sep 30, 10:34
- on Is It A Scam? Romance Scam Diagnostic – v2: “Carole, as you move forward with your recovery, you will learn how this all works. It was not your fault.…” Sep 29, 17:37
- on Is It A Scam? Romance Scam Diagnostic – v2: “I was blinded by such clever manipulation” Sep 29, 15:15
- on The SCARS Institute Relationship Scams Formula Checklist – 2026: “As I read this I could see myself in every step with my scam. I gained a lot more knowledge…” Aug 28, 19:51
- on The Persistence of Danielle Delaunay as a Fake Identity – 2026: “Unfortunately, you are being scammed. She is using a fake name regardless. At this point, your best option is to…” Aug 26, 20:16
- on The Persistence of Danielle Delaunay as a Fake Identity – 2026: “Dear Sirs, I have met this woman with the name Abigail Boateng in Ghana. I have an intensive mail contact…” Aug 26, 12:28





Thank you for your comment. You may receive an email to follow up. We never share your data with marketers.