Every year security researchers publish the list, every year it is the same list, and every year it works for the criminals. Digital Shadows, a threat-intelligence firm, reported in June 2022 that about 24 billion username-and-password pairs are circulating on criminal marketplaces, 65 per cent more than in 2020, and that the most common passwords among them are the ones you would guess.
The top ten
- 123456
- 123456789
- qwerty
- 12345
- password
- qwerty123
- 1q2w3e
- 12345678
- DEFAULT
- 111111
Roughly one in every 200 leaked passwords is "123456". Criminals do not guess these; they run "credential stuffing" tools that try a leaked email and password on hundreds of other sites automatically, and because most people reuse passwords, a leak from a forgotten forum opens a Gmail, a Facebook and, increasingly, a mobile-banking login.
The Bangladesh version of the problem
The local lists are no better; "dhaka1234", a phone number, or a birth year are the standard choices, and the five-digit PIN on bKash, Nagad and Rocket accounts is often a date of birth that is printed on the NID card in the same wallet. Facebook account takeovers, the most common cyber complaint at Dhaka police stations, almost always begin with a reused or guessable password rather than any clever hacking.
Five rules that actually work
- Length beats complexity. Three or four unrelated words, "mango-rickshaw-tuesday-lamp", are far harder to crack than "P@ssw0rd1" and easier to remember.
- Never reuse. One password per account. The leak that matters is the one from a site you forgot you joined.
- Use a password manager. Bitwarden is free and works on Android, iPhone and every browser; it generates and remembers the unique passwords so you do not have to.
- Turn on two-step verification on Facebook, Google, WhatsApp and your bank app. An authenticator app is safer than SMS codes, which SIM-swap fraud can intercept.
- Check whether you have already leaked. Enter your email address at haveibeenpwned.com; if it appears in a breach, change that password everywhere it was used.
The list will be the same again next year. The only question is whether your password is on it.




