Experts Analyze Over 5 Billion Leaked Passwords
In a recent study, experts examined approximately 5.1 billion unique login/password pairs. In this context, the login refers to an email address. Since the first password study in 2017, a total of 33.3 billion login/password pairs (including non-unique ones) have been analyzed.
The data sources for this analysis include various communities focused on password recovery from hashes (such as hashes.org and hashkiller.io) and underground forums where large-scale leaks are made publicly available.
The data is cleaned of “junk” (empty and duplicate entries). A special algorithm (filter) is used to identify and disqualify automatically generated passwords (those set by the service that suffered the leak, not by users themselves), as well as mass automated registrations (when accounts are created by bots on the affected service). Cyrillic characters are standardized to a single encoding.
Major Leaks in 2020
Notable leaks (over 30 million login/password pairs) included in this study for 2020:
- Virtual pet community neopets.com – 68 million
- Social network netlog.com – 53 million
- Online community for writers and readers wattpad.com – 48 million
- Photo sharing service fotolog.com – 42 million
- Social network livejournal.com – 33 million
Note: The numbers above represent the count of “decrypted” passwords available at the time of the study, not the total size of the original leaks. Some of these leaks may have occurred before 2020 but only became publicly accessible that year.
Password Database Statistics
- 5,108,611,469 total passwords (previously 4,883,711,954)
- 848,134,618 passwords contain only digits (previously 779,281,749)
- 1,335,889,957 passwords contain only letters (previously 1,275,706,800)
- 13,381,165 passwords contain Cyrillic letters (previously 10,972,555)
- 171,246,021 passwords contain letters, digits, and special characters (previously 159,948,243)
- 3,300,865,676 passwords are 8 or more characters long (previously 3,126,556,695)
- 840,680,047 passwords are longer than 10 characters (previously 792,123,298)
- 1,091,415,435 passwords are shorter than 7 characters (previously 1,031,293,444)
Most Popular Passwords of All Time
- 123456
- 123456789
- qwerty
- 12345
- password
- 12345678
- qwerty123
- 1q2w3e
- 111111
- 123123
Notably, “123123” entered the top 10, pushing “1234567890” down to 12th place.
Top 25 Most Popular Passwords of All Time
- 1234567
- 1234567890
- 000000
- qwertyuiop
- 123321
- 1234
- abc123
- 654321
- 666666
- 1q2w3e4r5t
- 7777777
- password1
- iloveyou
- 555555
- 123
Top 10 Passwords from 2020 Leaks
- 123456
- 123456789
- 111111
- Password
- 12345678
- 123123
- 12345
- 1234567
- 000000
- 1234567890
Top 10 Passwords Containing Only Letters
- qwerty
- password
- qwertyuiop
- iloveyou
- asdasd
- zxcvbnm
- qazwsx
- dragon
- asdfghjkl
- monkey
The password “unknown” (previously ranked 7th) was disqualified this year due to the filter.
Top 10 Passwords with Letters, Digits, and Special Characters
- 1qaz@WSX
- P@ssw0rd
- p@ssw0rd
- 1qaz!QAZ
- !QAZ2wsx
- Pa$$w0rd
- Password1!
- feder_1941
- !qaz2wsx
- abc123!
Several passwords from last year’s complex password ranking were disqualified this year by the filter, including “Aa123456.”, “)4ever”, “123456QQAqqa_”, “Spiritwear_2004”, “wowecarts@123”, and “film@123”.
Top 10 Cyrillic Passwords
- йцукен
- пароль
- я
- любовь
- привет
- наташа
- максим
- люблю
- марина
- андрей
Top 10 Passwords Disqualified by the Filter
- g_czechout
- DEFAULT
- 30media
- 10pace
- 59trick
- 24crow
- 59mile
- 19weed
- 66bob
- )ryan
Impact of COVID-19 on Passwords
The most significant event of last year was, of course, the COVID-19 pandemic. It’s interesting to see how the pandemic influenced user passwords.
Top 25 Passwords Related to Coronavirus and the Pandemic
- covid19
- корона
- epidemic
- COVID19_Access
- Covid19
- pandemic
- covid-19
- coronavirus
- COVID19
- covid2020
- epidemic5
- Covid2020
- epidemic1
- эпидемия
- pandemic1
- coronavirus1
- covidien
- covid2019
- Covid-19
- Coronavirus2020
- Covid2019
- Pandemic
- covid192020
- coronavirus19
- covid1984
Most Popular Logins (Email Addresses)
Top 10 Email Domains
- yahoo.com
- gmail.com
- hotmail.com
- mail.ru
- rambler.ru
- yandex.ru
- ya.ru
- qq.com
- aol.com
- bk.ru
There were no significant changes in the top 10 domains, only some entries swapped places.
Top 10 Most Popular Names
- info
- admin
- office
- contact
- sales
- adam
- webmaster
- john
- chris
The names “rambler.ru” and “mail.ru” were removed from this list as they were filtered out this year.