X
Tech

Meet the worst 100 passwords from the Ashley Madison hack

And, what a surprise, they're about as inventive (and easy to crack) as "123456."
Written by Zack Whittaker, Contributor

A list of the worst passwords in the Ashley Madison breach just got longer -- and a lot more depressing.

Security research group CynoSure Prime were able to find out the most common passwords that were used on Ashley Madison, a site which helps married people cheat on their partners, which suffered a massive data breach earlier this year when it was targeted by hackers.

The list of the 100 most commonly-used passwords was first posted on Ars Technica.

As many as 36 million passwords were leaked, but they were hashed, meaning they were cryptographically scrambled using a feature known as bcrypt. An earlier analysis of just 4,000 decrypted passwords (about 0.0006 percent of the entire cache) took days of constant crunching. By comparison, 2.6 million of the hashed passwords were cracked with just one computer in a mere few hours.

But by analyzing the source code of the site -- also leaked in the data dump -- the researchers found that some of the login tokens used MD5, a far weaker hashing algorithm.

"Instead of cracking the slow bcrypt hashes directly, which is the hot topic at the moment, we took a more efficient approach and simply attacked the [MD5] tokens instead," the researchers wrote.

At the time of the team's posting on Thursday, more than 11.2 million passwords had been successfully hacked, or about one-third of the total cache. With that in mind, the list will likely change slightly over time.

Password Times used
123456 120,511
12345 48,452
password 39,448
default 34,275
123456789 26,620
qwerty 20,778
12345678 14,172
abc123 10,869
p***y 10,683
1234567 9,468
696969 8.801
ashley 8,793
f**kme 7,893
football 7,872
baseball 7,710
f**kyou 7458
111111 7,048
1234567890 6,572
ashleymadison 6,213
password1 5,959
madison 5,219
a**hole 5,052
superman 5,023
mustang 4,865
harley 4,815
654321 4,729
123123 4,612
hello 4,425
monkey 4,296
000000 4,240
hockey 4,191
letmein 4,140
11111 4,077
soccer 3,936
cheater 3,908
kazuga 3,871
hunter 3,869
shadow 3,831
michael 3,743
121212 3,713
666666 3,704
iloveyou 3,671
qwertyuiop 3,599
secret 3,522
buster 3,402
horny 3,389
jordan 3,368
hosts 3,295
zxcvbnm 3,280
asdfghjkl 3,174
affair 3,156
dragon 3,152
987654 3,123
liverpool 3,087
bigd**k 3,058
sunshine 3,058
yankees 2,995
asdfg 2,981
freedom 2,963
batman 2,935
whatever 2,882
charlie 2,860
f**koff 2,794
money 2,686
pepper 2,656
jessica 2,648
asdfasdf 2,617
1qaz2wsx 2,609
987654321 2,606
andrew 2,549
qazwsx 2,526
dallas 2,516
55555 2,501
131313 2,498
abcd1234 2,489
anthony 2,487
steelers 2,470
asdfgh 2,468
jennifer 2,442
killer 2,407
cowboys 2,403
master 2,395
jordan23 2,390
robert 2,372
maggie 2,357
looking 2,333
thomas 2,331
george 2,330
matthew 2,298
7777777 2,294
amanda 2,273
summer 2,263
qwert 2,263
princess 2,258
ranger 2,252
william 2,245
corvette 2,237
jackson 2,227
tigger 2,224
computer 2,212

(Passwords is via Ars Technica)

Editorial standards