Page 1475 - (ISC)² CISSP Certified Information Systems Security Professional Official Study Guide
P. 1475
common passwords on the internet. Some of these are shown in the
sidebar “Most Common Passwords.”
Most Common Passwords
Attackers often use the internet to distribute lists of commonly
used passwords based on data gathered during system
compromises. Many of these are no great surprise. The firm
SplashData produces an annual list of the top 100 passwords found
in files stolen during data breaches. Here are the top 10 passwords
on that list from 2017:
1. 123456
2. password
3. 12345678
4. qwerty
5. 12345
6. 123456789
7. letmein
8. 1234567
9. football
10. iloveyou
These are real passwords, used by real people, on real websites in
2017! Remarkably, SplashData also estimated that the top 25
passwords on the list made up 10 percent of all the passwords
found in breach files.
Finally, a little knowledge about a person can provide extremely good
clues about their password. Many people use the name of a spouse,
child, family pet, relative, or favorite entertainer. Common passwords
also include birthdays, anniversaries, Social Security numbers, phone
numbers, and automatic teller machine (ATM) personal identification
numbers (PINs).

