Company employee writing code on a screen.
© DC Studio/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

A new study by NordPass has found that some of the largest companies around the world continue to use weak and oftentimes silly passwords. The study looked at the business account passwords of companies across 20 industries and 31 countries.

It revealed that 68% of the subjects had weak passwords (made up of simple combinations of letters, numbers, and names), with “password” and “123456” being the most common on the list. A significant portion of the passwords (32%) referenced a specific company name.

The study casts a worrying light on the state of password hygiene in large corporations. Most companies today have mandatory cybersecurity training modules for employees, along with seminars, to raise security awareness.

Despite these initiatives, NordPass claims business accounts of some of the world’s biggest companies continue to use unsecured passwords.

“The workplace is all too often plagued by cybersecurity breaches, and one of the main culprits is poor password management,” NordPass states on its website.

“Despite the widespread recognition that weak and reused passwords are a major contributing factor, businesses of every size continue to neglect their password ‘hygiene.’ It’s time for companies to prioritize this crucial aspect of their digital security and take proactive measures to protect themselves from potential cyberattacks.”

About the NordPass Study

NordPass worked with a third-party company to analyze cybersecurity data belonging to the world’s 500 largest companies by market cap. The researchers organized the data according to industry, 20 in total, and published the top 20 passwords in each industry.

Apart from general trends such as the use of weak passwords and using company names, certain industries had curious password trends. For example, “dummies” was one of the most prominent passwords in the consumer goods industry. In the financial sector, “vacation” and “ready2go” were among the top 20 passwords. The energy industry had “snowman” as the 11th most used password.

The widespread use of company names — whether it be their domains, full names, or abbreviations — is a very alarming trend. This makes it easier for hackers to brute force their way into these accounts. Cybercriminals see business accounts as a financial treasure trove.

A compromised account can allow a bad actor to travel laterally or up a company’s corporate network. Once they breach the network, they can carry out a variety of malicious activities, such as stealing sensitive information, deploying ransomware, or carrying out cyber espionage.

Tips to Secure Your Business and Personal Accounts

NordPass has four major tips to keep your accounts safe. First, ensure your passwords consist of at least 20 characters combining letters (uppercase and lowercase), numbers, and special characters.

Second, enable MFA or multi-factor authentication to add an additional layer of security in case someone gets access to your password. Experts advise relying on biometrics or face scans instead of SMS or voice confirmation.

In fact, passwords are on the road to extinction as a number of big-name tech companies, like Apple and Google, are starting to offer passkeys as an alternative. A large number of North Americans have also shown an interest in passwordless sign-ins.

Business accounts should implement effective privilege controls to ensure only employees or management with the right credentials can access sensitive material.

Finally, using a password manager is a convenient and effective way to manage the numerous sign-up details we create and use for our online activities. You can check out our detailed NordPass review to learn more about its features. Additionally, we recommend reading the following material for more information on Nord’s security suite:

  • NordVPN Review: Great VPN, Dark Web Monitoring, and Threat Protection
Leave a comment