Recently, Adobe users’ details were stolen during an attack on the company.
About 1.9 million people used “123456” sequence, according to analysis of data lost in the leak.
Online copies of the data have let security researchers find out more about users’ password-creating habits.
The analysis suggests that many people are making it easy for attackers by using easy-to-guess passwords.
On October 4, Adobe reported that its systems had been penetrated by attackers who had stolen the online credentials for millions of its users.
Early reports suggested about 2.9 million records had been compromised.
On October 30, this figure was revised; with Adobe saying information about 38 million active users had gone astray.
In total, information about more than 150 million accounts was stolen – but many of the other accounts were disused, abandoned or duplicates.
Adobe has now shut down all the compromised accounts, saying it will only reopen them once passwords have been changed.
Copies of the data that was exposed by the breach have begun circulating online and inspired security researcher Jeremi Gosney to go through it working out which password was most popular.
Top of the list, with 1.9 million entries, was the “123456” string of numbers. Second was the slightly longer “123456789” sequence.
Other popular easy-to-guess passwords included “adobe123”, “qwerty” and “password”.
Jeremi Gosney said the results of the analysis should be treated with caution because, so far, no-one had access to the keys that Adobe used to encrypt the data.
However, he added, flaws in the way Adobe had stored and encrypted passwords along with clues in the giant file of data had made it possible to draw up a list that he was “fairly confident” was accurate.
Computer security researchers who study password-creating habits have also seized on the data dump as a way to refine the word lists they use to attack login systems in a bid to make them more secure.
Lists of passwords and email addresses are a boon to attackers not just because they can be used to get access to the systems they were supposed to secure. Many people re-use the same password for different services potentially giving attackers a way into other networks.
Top 20 passwords
The US House Ethics Committee has voted to release its report on former Republican Representative…
ABC News has agreed to pay $15 million to President-elect Donald Trump to settle a…
South Korea’s parliament has voted to impeach President Yoon Suk Yeol over his failed attempt…
Israeli war planes have carried out more than 100 air strikes in Syria on December…
President-elect Donald Trump has threatened to impose 100% tariffs on the BRICS countries if they…
Syrian troops have withdrawn from the city of Aleppo following an offensive by rebels opposed…