WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Perpetual Password Pitfalls
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Perpetual Password Pitfalls

Author: Jennifer Walker

Created: Thursday, July 2, 2020 - 17:59

Categories: Cybersecurity

While phishing for credentials is a top cyber attack vector, many threat actors do not need to rely on phishing because password guessing is so easy. Threat intelligence firm Flashpoint took a deep dive into its collection of over 35 billion compromised credentials and unsurprisingly discovered a primary parallel: people are predictable.

After slicing and dicing the top 10,000 bad passwords, Flashpoint observed:

  • The top 450 most repeated passwords included keyboard patterns, number strings, and first names.
  • The next most common types of passwords consisted of single dictionary words, patterns including sports references, site names, and variations on the word password.
  • Over 96% of the top 10,000 most reused passwords were fewer than 12 characters long.

While the findings themselves are commonly published and unsurprising, it is astonishing that even a pool of more than 35 billion credentials yields the same perpetual password pitfalls. Furthermore, due to our propensity to procrastinate changing our passwords, threat actors have a lot of success out of just one cache of compromised credentials – quite honestly, if you’ve seen one, you’ve seen them all. Not only are passwords predictable and persistent, but widespread password reuse only perpetuates the problem. Read the post at Flashpoint

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar