---
title: "Hacked Passwords/Bad Passwords"
canonical: https://romancescamsnow.com/hacked-passwords-bad-passwords/
type: post
author: "SCARS Institute Editorial Team"
published: 2022-07-04
modified: 2023-02-11
categories: ["Online Safety", "2022", "Data Theft & Data Breaches", "Insights"]
summary: ""
organization: "SCARS Institute - Encyclopedia of Scans - World's #1 Anti-Scam Website - Romance Scams NOW"
organization_url: https://romancescamsnow.com/
llms: https://romancescamsnow.com/llms.txt
---

# Hacked Passwords/Bad Passwords

# Hacked Passwords

## Common Passwords That Hackers Already Know

## Is Yours In The List?

### A SCARS Insight

## Most Hacked Passwords Revealed

## Exposed as UK cyber survey exposes gaps in online security

The U.K. National Cyber Security Centre's (NCSC) global hacked password risk list

- Breach analysis finds 23.2 million victim accounts worldwide used only '123456' as a password
- Global password risk list published to disclose passwords already known to hackers
- SCARS and the NCSC urge using 3 random words as passwords

## Why is password reuse a problem?

Because they easily turn into hacked passwords!

Password reuse is still a major risk for individuals and companies. The password '123456' has been found 23 million times in the breaches that was collected. You might think that choosing a more complex password such as 'oreocookie' is better, but even that has been seen over 3,000 times.

Attackers commonly use lists like those of easily hacked passwords when attempting to breach a perimeter, take over an account, or when trying to move within a network to potentially less well-defended systems. It's especially common in networks where there's a corporate component. In such deployments, attackers have been able to breach the corporate network and move laterally to the internal network due to poor network segmentation, where a single weak point (such as a password from one of these lists on a box in a DMZ) has enabled traversal. In the first occurrence of the TRITON/TRISIS malware, the attacker breached the external perimeter VPN and then pivoted internally using RDP due to poor segmentation.

But they also do exactly the same things to take over social media accounts, access online banking, or many other accounts of high value to cybercriminals.

## More than half of the people online do not use a strong, separate password for their main email account! Email is one of the most valuable accounts users have!

They were all easy for hackers, bots, and automated password breakers to guess and apply to gain access to important accounts.

### Upgrade your passwords NOW! [Learn more about passwords here.](https://romancescamsnow.com/dating-scams/scarsrsn-cyber-basics-creating-a-safe-password/)
