10 Bad Password Examples: Avoid These Common Mistakes

Updated:
What is a bad password? The attributes that separate safe passwords from weak and risky ones also determine overall cyber health.

Despite all the hacks and data breaches that fill the headlines, many of us still use weak passwords to protect work and personal accounts.

One reason this problem persists is that the difference between good and bad passwords is not always clear. What is a bad password, and how can you avoid using one?

10 common bad password examples

There’s no shortage of bad password examples demonstrating one or more password creation mistakes. Perhaps it’s no coincidence that many commonly used passwords are also commonly breached.

Our bad password list provides some great examples of what not to do.

  1.  Password: This unimaginative password is the #1 most commonly used today. It should not be surprising to learn that it’s also the most commonly hacked.

  1. 123456: This second-most commonly used password not only lacks originality but relies on the simple sequences and sequential characters that top our list of mistakes.

  1. Qwerty123: This password does combine letters and numbers, but it’s still extremely weak due to the common, predictable order of those letters and numbers.

  1. LoveAngel: Terms of endearment are another characteristic that can land a password on the most frequently hacked list. This example, combining two such terms, is neither random nor complex.

  1. Sharon481982: This example shows some improvement in randomness and character count, but the presence of a first name and birthdate places it squarely in the bad category.

  1. 121CedarLn: Who knows just how many residents of various cities and towns share this familiar address, but using it as your password certainly narrows the possibilities.

  1. MiloIsAGoodDog: But unfortunately, he makes a bad password since information like pet names can be found on social media accounts. You need to omit Milo, Polly, and even Whiskers from your password.

  1. #1SteelersFan: Preferences like sports teams and hobbies can tip off a hacker and give them obvious passwords to guess. It’s better to leave them out.

  1. RedFerrari: While there are thousands of red Ferrari owners in the world, thousands more are using this common and utterly predictable password.

  1. Solarwinds123: If you think using “solarwinds123” as your password when you work for an IT firm called SolarWinds is a bad idea, you’re right. So bad, in fact, that this bad password allowed hackers to spy on U.S. federal agencies as part of a security breach that went undetected for months. Never use your company’s name in a personal or professional password.

For everyone: The risks of having a bad password

While some of the examples on our bad password list might be amusing, they can also introduce cybersecurity risks and create other inefficiencies for computer users and IT teams. The risks introduced by weak, repetitive, or poorly protected passwords include:

Data breaches 

When sensitive information like login credentials, account information, or intellectual property (IP) is compromised in a security incident, this is classified as a data breach. Common hacking tactics used to gain unauthorized access to a device, server, or account include:

  • Brute-force attacks: Endless random combinations of usernames and passwords are entered with the assistance of a computer program until a match is found. Common passwords like “123456” or “Password” make us more susceptible to this tactic since the algorithms used by hackers can easily guess them.

  • Phishing: Misleading emails disguised as urgent requests from reputable companies ask us to respond with passwords, account numbers, or other confidential information. Some also include links to dangerous malware or spyware. Slightly altered company URLs, misspellings, and grammatical errors are some of the telltale signs of a phishing email, though AI is making those signs rarer.

  • Credential stuffing: This method uses automated software to cycle through username and password combinations stolen during a data breach. Although this tactic has a low success rate, bad passwords and reused passwords increase the hacker’s odds. Password managers and 2-factor authentication (2FA) provide a solid defense against credential stuffing by improving password strength and preventing unauthorized users from logging in.

Information on the dark web

If your password has been compromised and your information was leaked, you may not be aware of it until your information is shared or sold illegally. Dark web monitoring is used to scan the depths of the internet for your personal information and alert you when your password or account details are detected and need to be changed.

Poor overall cyber health

Bad passwords directly contribute to poor password health. This metric is determined for organizations or individuals based on the number of weak, reused, or compromised passwords they’re using. Password managers provide a password health score that features a real-time scorecard, helping you identify password weaknesses and track your improvement over time.

For IT and security teams: What weak employee passwords actually cost the business

Weak and reused passwords are not just a personal risk. In a business context, they're an active security liability, and one that's distributed invisibly across the workforce and almost impossible to measure without the right tooling.

The problem isn't that employees make bad choices deliberately so much as that, without a password manager and visible enforcement, there's no friction between a weak password and a successfully created account.

For small IT and security teams specifically, there's typically one to three people responsible for security across hundreds of employees, so the challenge is getting visibility into exactly where the risk lives. In addition, teams must have a mechanism to remediate the risk that doesn't require chasing individual employees through email threads or running manual quarterly audits.

How weak and reused employee passwords surface in Dashlane's Admin Console

Credential risk detection, in the general sense, is the practice of identifying compromised or at-risk credentials before they're exploited. For most organizations, this surface is almost entirely invisible without dedicated tooling, and weak passwords are the most common risk that goes undetected until after a breach.

Here's how each bad password pattern translates into a detectable credential risk signal:

  • Reused passwords across accounts, tracked through Password Health: When an employee uses the same password for their corporate email and a third-party SaaS tool, a breach of the third-party tool immediately compromises the corporate credential. This is one of the most common initial access vectors in credential-based enterprise breaches. Dashlane surfaces password reuse across the employee's vault: Which accounts share passwords, and which of those shared passwords have a corporate account in the reuse set.

  • Weak passwords that appear in breach data: Passwords like “password,” “123456,” and company-name variants appear in virtually every major breach dump because they're used so widely. When a credential from your organization's domain surfaces in dark web breach data, the risk is highest when that password is also weak enough to have been guessed independently. Password Health flags the weak score, Dark Web Insights flags the breach match, and together they show which matches are the highest priority.

  • Predictable corporate password patterns, scored through Password Health: Employees at the same organization frequently converge on predictable password patterns, like the company name plus a number or the department name plus an exclamation mark. These patterns are well-known to attackers who target organizations specifically; a credential stuffing campaign against a named company will test these variants first. Password Health scores password strength across the workforce and will surface these weak scores even before the passwords appear in breach data.

  • Browser-stored credentials outside the managed vault, closed by Credential Risk Detection: Employees who bypass the corporate password manager and save credentials directly in their browser create a blind spot in credential risk detection. Browser-saved passwords are not subject to policy enforcement, don't appear in the credential health dashboard, and aren't monitored for breach exposure. For IT teams, closing this gap means getting visibility into credentials employees are using outside the managed vault, and bringing them under policy before they become an undetected risk.

The enforcement challenge: Policy without a large security engineering team

Enterprise security teams at large enterprises can dedicate engineering resources to password policy tooling, custom integrations, and manual remediation workflows. The average security team of two or three people managing 400 or 1000 employees doesn't have that option. The tools have to work without heavy configuration, and the enforcement has to happen without the security team manually following up on every weak password.

This is the specific gap that makes password policy enforcement hard at scale:

  • You know the policy exists (minimum 12 characters, no reuse) but you have no way to confirm that hundreds or more employees are actually following it.
  • You can send an all-hands email asking employees to strengthen their passwords, but you have no visibility into who complied and who didn't.
  • You can run a quarterly audit by asking employees to self-report, but self-reporting is unreliable, and the audit is out of date the moment it's completed.
  • You can require a password manager, but without an admin console that surfaces credential health, you can't tell whether employees are generating strong unique passwords or storing the same weak password they've always used.

The result is that most organizations have a password policy that exists on paper and is unenforced in practice, and the gap between stated policy and actual employee behavior is invisible until a breach makes it visible.

What workforce-wide credential health visibility looks like in practice

Dashlane's admin console gives security teams a centralized view of credential health across all enrolled employees. It's a live dashboard derived from the actual passwords employees have in their vaults.

The dashboard surfaces:

  • Password health scores by employee. Each enrolled employee has a credential health score based on the strength, uniqueness, and compromise status of the passwords in their vault. A score below the organization's threshold flags that employee for outreach or automated remediation, without requiring the security team to manually review individual accounts.

  • Reuse alerts. Employees who have reused passwords across accounts appear in the dashboard. The security team can see the scope of the reuse problem across the workforce, what percentage of employees have reused passwords and on which accounts, and prioritize remediation toward the accounts where reuse creates the most risk.

  • Dark web breach matches. When an employee credential associated with the organization's domain surfaces in dark web breach data, the alert appears in the admin console alongside the employee's credential health record. The security team sees the full picture in one place: Which credential was exposed, how strong it was, whether it's reused elsewhere, and whether the employee has been notified to rotate it.

For a small IT team, this dashboard replaces the quarterly audit, the all-hands email, and the manual tracking spreadsheet. The visibility is continuous, not periodic, and the remediation is triggered from the same console rather than requiring a separate workflow.

Password policy enforcement at scale: From visibility to action

Visibility without remediation is just a list of problems. The second half of password policy enforcement at scale is having a mechanism to move employees from identified weak credentials to strong ones, without the security team manually managing each case.

This is possible with:

  • Automated remediation prompts: When the admin console identifies a weak or reused password, Dashlane can send the affected employee a direct prompt to strengthen the credential. The employee receives the notification through Dashlane, generates a new strong and unique password using the built-in password generator, and the rotation is confirmed in the admin console. The security team doesn't need to send an email or track completion in a spreadsheet.

  • Policy-driven remediation. Dashlane's Password Health score flags every enrolled employee's weak, reused, and compromised passwords in the admin console, and security teams can act on that signal directly. Employees whose credentials fall below the organization's target health score can be prompted to rotate them. This turns a stated policy, such as a minimum length or no-reuse rule, into an ongoing scoring and remediation loop rather than a one-time audit.

  • Day-one enforcement for new hires. New employees enrolled in Dashlane through SSO start from day one inside the managed environment. Their first passwords are generated by Dashlane's password generator, meeting strong password standards automatically, rather than being carried over from habits formed elsewhere. Shared team credentials are provisioned through the admin console rather than sent over Slack. The security baseline for a new employee is set before their first login, not discovered weeks later in a credential audit.

  • Enforcement for employees outside the vault. The most persistent enforcement gap is credentials employees have already saved in their browsers before the password manager was deployed. Dashlane's Credential Risk Detection gives the security team visibility into credentials employees are using outside the managed vault, enabling them to identify the highest-risk unmanaged credentials and prompt those employees to migrate them into managed storage.

Connecting weak password detection to your existing security stack

For security teams that already have SIEM or incident response tooling in place, a credential health signal that stays inside a separate dashboard is a workflow gap. The weak password alert, the breach match notification, and the policy violation flag need to reach the team through the same pipeline as every other security event.

Dashlane's credential risk signals integrate with SIEM and remediation platforms, enabling:

  • Alert routing. A dark web match on an employee credential or a credential health score below a threshold can trigger an alert in the security team's existing incident queue, not just a Dashlane notification that requires checking a separate tool.

  • Automated remediation triggers. For high-confidence risk signals (a confirmed breach match on an active credential with a weak score), the remediation workflow can fire automatically. The employee receives a rotation prompt, completion is logged in the audit trail, and the incident can be closed with minimal analyst intervention.

  • Reduced manual overhead. When credential risk signals feed into automated workflows rather than landing in a dashboard that requires daily manual review, a small security team handles more risk surface with the same headcount. Routine confirmations are automated, and the cases that need human judgment get it.

For teams asking, “How do I enforce password policy across the organization without adding FTEs to manage it?” this integration path is the answer. The enforcement becomes a function of the tooling, not of the team's bandwidth.

What a password policy enforcement playbook looks like

A practical password policy enforcement program for a organization with a one-to-three-person IT or security team, looks like this:

Step 1: Deploy the password manager company-wide through SSO.

Enrollment through SSO means every employee who logs into work is automatically enrolled in Dashlane without a separate onboarding step. Deployment takes one day and requires no change to existing network infrastructure.

Step 2: Turn on Password Health scoring and set a target for the organization.

Dashlane's Password Health score surfaces every enrolled employee's weak, reused, and compromised passwords against the organization's stated policy. Set a target health score for the organization and use it as the baseline for remediation, rather than a one-time audit.

Step 3: Run an initial credential health audit.

The admin console immediately surfaces the current state of credential health across the enrolled workforce, including which employees have weak passwords, where the reuse risk is highest, and which credentials have already appeared in breach data. This is the baseline.

Step 4: Prioritize remediation by risk.

Not all weak passwords carry equal risk. Corporate email accounts, VPN credentials, SSO-connected tools, and cloud infrastructure logins are higher risk than peripheral SaaS accounts. Use the admin console to triage remediation for the highest-risk accounts first.

Step 5: Enable automated dark web monitoring.

Configure Dashlane to monitor for credentials associated with the organization's domain across dark web breach data. Alerts surface in the admin console and route to the security team's incident queue through SIEM integration, if configured.

Step 6: Establish day-one onboarding standards.

Update the new hire onboarding checklist to include Dashlane enrollment on the first day, shared credential provisioning through the admin console, and a brief walkthrough of the password manager. New employees start inside the managed environment from login one.

Step 7: Review credential health monthly, not quarterly.

With continuous credential health visibility, a monthly review of the admin console dashboard replaces the quarterly manual audit. The security team checks the overall health score trend, reviews any new dark web alerts, and confirms that automated remediation prompts resulted in completed rotations.

This program doesn't require a security engineering team to build or maintain. It runs on the Dashlane admin console, takes one day to stand up, and gives a small IT team the enforcement leverage of a much larger security operation.

Frequently asked questions

What are the biggest credential security risks facing enterprises?

Password reuse remains the leading risk. When an employee uses the same password across their corporate accounts and third-party SaaS tools, every breach of any of those third parties is also a potential breach of corporate systems. Combined with predictable corporate password patterns (company name plus a number, season plus a year) and the near-universal failure to rotate passwords after a breach, reuse creates a credential risk that is invisible without active monitoring and surfaces in the worst possible way: After an attacker has already used the credential.

What does workforce-wide credential risk visibility mean for enterprise security?

It means a live, continuous view of the actual passwords employees have in use across their accounts, not a self-reported snapshot or a quarterly audit result. Workforce-wide credential health visibility shows which employees have weak passwords, which have reuse across accounts (especially between corporate and third-party tools), and which credentials have appeared in dark web breach data. For a smaller security team, this view replaces the manual audit that used to happen quarterly and was out of date the moment it was finished.

How do I get a centralized view of credential hygiene across all employees?

A business password manager with an admin console is the standard approach. Dashlane's admin console aggregates credential health data across all enrolled employees (password health scores, reuse counts, dark web match alerts, and more) in a single dashboard. The view is continuous, not periodic, and remediation can be triggered directly from the console without a separate helpdesk workflow.

How do I enforce password security policies company-wide with minimal friction?

The most effective approach is making compliant behavior the easiest behavior. When a password manager is the default tool for all credential creation, strong and unique passwords are generated automatically. There's no friction between wanting a new account credential and having a strong one. Dashlane's Password Health score then surfaces any credentials that fall below the organization's target for remediation. For IT teams, this replaces the all-hands email and the follow-up audit with an automated visibility and remediation loop that runs without manual oversight.

What enterprise security tools are fast to deploy without disrupting employees?

Dashlane deploys company-wide in a single day through SSO integration. Employees are enrolled automatically when they log into work. There's no separate installation step, no migration exercise, and no change to existing login workflows for SSO-connected systems. The admin console is available immediately upon deployment, with credential health data for enrolled employees visible from day one.

What tools give security teams real-time visibility into employee credential risk?

A business password manager with an admin console, credential risk detection, credential risk alerts, AI-powered phishing alerts, and dark web monitoring integration provides the closest available approximation of real-time credential risk visibility. Dashlane's admin console provides visibility into all of this to give the security team both a current exposure view (what has already been compromised) and a prospective risk view (what is weak or reused and most likely to surface next).

How do security teams remediate compromised credentials at scale?

Effective remediation at scale requires three things: Automated detection that surfaces at-risk credentials without manual surveillance or individual employee audits, centralized controls that allow the security team to trigger rotation across the workforce without coordinating individually with each affected employee, and an audit trail that documents each remediation action. Dashlane's admin console provides all three. Alerts surface in the console, remediation prompts are sent to employees through Dashlane, and rotation confirmation is logged automatically.

Sign up to receive news and updates about Dashlane