Skip to content
Monday 7 September 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE · FR
MorningWire

European business, markets and politics

FTSE 100
10,830.89
0.00%
DAX
25,957.01
-0.34%
CAC 40
8,283.66
+0.06%
STOXX 50
6,382.35
-0.17%
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
More
GermanyFranceEU InstitutionsCompetitionPublic AffairsBankingTechnologyEnergy
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
  • DE
Sunday 21 April 2019 1:16 pm  |  Updated:  Monday 03 June 2019 12:51 am

Millions use 123456 as a password, UK spy study finds

By: James Warrington

Add as a preferred source on Google

It’s 2019, but millions of Brits are still using simple passwords that could easily be hacked.

A survey carried out by the National Cyber Security Centre (NCSC) revealed more than 22m people across the UK used 123456 as a password, making it the most common password used for breached accounts.

Read more: Government urges businesses to ramp up cyber security

Millions of people also opt for easy-to-guess words such as “qwerty” and “password”, according the the study, which analysed accounts that had fallen victim to cyber security breaches.

The findings exposed huge gaps in cyber security knowledge, and the NCSC urged people to use three random words to create a secure password.

The most common name to be used in passwords was Ashley, which featured in more than 432,000 accounts, with Michael and Daniel following closely behind.

Liverpool was crowned champion among Premier League football teams, while Blink 182 and Superman were also common passwords.

Most used overall Names Premier League football teams Musicians Fictional characters
123456 (23.2m) ashley (432,276) liverpool (280,723) blink182 (285,706) superman (333,139)
123456789 (7.7m) michael (425,291) chelsea (216,677) 50cent (191,153) naruto (242,749)
qwerty (3.8m) daniel (368,227) arsenal (179,095) eminem (167,983) tigger (237,290)
password (3.6m) jessica (324,125) manutd (59,440) metallica (140,841) pokemon (226,947)
1111111 (3.1m) charlie (308,939) everton (46,619) slipknot (140,833) batman (203,116)

“Password re-use is a major risk that can be avoided – nobody should protect sensitive data with something that can be guessed, like their first name, local football team or favourite band,” said Dr Ian Levy, NCSC technical director.

“Using hard-to-guess passwords is a strong first step and we recommend combining three random but memorable words. Be creative and use words memorable to you, so people can’t guess your password.”

The survey, which was published ahead of the NCSC’s cyber security conference in Glasgow this week, revealed just 15 per cent of people feel they know a great deal about how to protect themselves online, while 42 per cent expect to lose money to fraud.

Read more: A third of small businesses have no cyber security strategy

Web security expert Troy Hunt said: “Making good password choices is the single biggest control consumers have over their own personal security posture.

“Recognising the passwords that are most likely to result in a successful account takeover is an important first step in helping people create a more secure online presence.”

 

 

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Related Topics

Trending Articles

  • Iceland boss Richard Walker vows to set up shop on Falkland Islands

  • Britain ‘taxing itself to death,’ Burnham warned

  • £74m for branded condoms? UK must stop spaffing cash on foreign aid

  • Don’t underestimate the free trade agreement Britain just joined

  • Victoria Beckham owed £350,000 by Harvey Nichols

More from Morning Wire

  • Iranian hackers behind UK energy plant attack

    Energy
    UK industrial electricity prices are the highest in the G7 and 46 per cent above the average of the International Energy Agency.
  • Stansted Airport owner hit with cyber attack as millions of customers’ data stolen

    Transport & Infrastructure
    London Stansted Airport is part of the wider Manchester Airports Group (MAG).
  • AI gold rush leaves accountancy firms exposed to costly cyberattacks

    AI
    Two tablets displaying code and a cyber warning symbol, with blurry blue and pink background numbers
  • Cloudflare Partners with OpenAI Daybreak Models to Redefine Vulnerability Management with AI-Powered Edge Defense

    Business Wire
  • Andrew Bailey warns markets are not ready for the rise (or fall) of AI

    Markets
    Andrew Bailey, Governor of the Bank of England, in a suit and tie, looking thoughtful during a press conference.
  • Cloudflare Introduces Adaptive Intelligence; Reverses the Economics of Automated Cyber Attacks

    Business Wire
  • UK’s AI watchdog flags new OpenAI and Anthropic cyber alarms

    AI
    Smartphone displaying the Claude by Anthropic AI assistant app, showing the app icon and interface.
  • IGI Announces the Launch of Cipher, A Specialty Treaty Reinsurance Platform Focused on Cyber

    Business Wire
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • EU Institutions
  • Europe

Business

  • Markets
  • Business
  • Economy
  • Regulation
  • Competition
  • Public Affairs

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook