Insights

Your Password Is Still ‘Company123’ and AI Knows It

April 27, 2026

By Lucy Thomas-Animashaun, Consultant – Strategy & GRC
Sean Manning, Consultant – Identity and Access Management (IAM)

The cybersecurity industry spends billions every year on advanced threat detection, AI-powered defense platforms, zero-trust architectures, and next-generation endpoint protection. Conferences are packed with sessions on quantum-resistant encryption and agentic AI risk. The level of sophistication in modern security is remarkable.

And yet, “123456” remains the most commonly used password in the world. Five years running.1,2,3

There is a disconnect here that deserves more attention than it gets. Organizations are investing serious money in advanced capabilities while the fundamentals, the things that actually cause most breaches, remain embarrassingly neglected.

The Data Tells a Frustrating Story

Analysis of billions of leaked credentials paints a picture that is hard to ignore. Fifty-three million devices still had the default password “admin” and were never changed from the factory setting. Fifty-six million used the word “password.”4 A quarter of the top 1,000 most-used passwords consist of nothing but numerals. Nearly one in four Americans relies on some variation of “abc123,” “Iloveyou,” or “Qwerty.”5 Every one of those can be cracked in under a second.

In corporate environments, the numbers are equally concerning. Eighty-one percent of hacking-related breaches involve weak or reused credentials.6 Employees reuse the same password across an average of thirteen different systems.7 Nearly half of all data breaches across every industry start with a compromised password.

The industry is building sophisticated defenses against advanced threats while the most common attack vector remains, essentially, guessing.

Incidents That Should Not Have Happened

Statistics take on a different weight when attached to real incidents.

In late 2025, the Louvre suffered a $102 million jewelry theft. The password protecting the surveillance system was “Louvre.” Not a variation. Not a passphrase built around the name. Just the name of the building, unmodified, as the single credential standing between the cameras and a nine-figure loss.8

In South Korea, over 120,000 home and business cameras were compromised because default passwords were never changed.9 In India, a hospital’s CCTV system was breached using “admin123,” with deeply harmful consequences for patients whose footage was stolen and sold.10

The Dropbox breach that exposed sixty million user accounts began with one employee reusing a personal password at work. One recycled credential. Sixty million accounts.11

None of these involved sophisticated exploits or advanced persistent threats. They succeeded because someone tried the obvious password and it worked.

AI Changed the Math

What makes the current moment different from five years ago isn’t the password problem itself. Passwords have been flawed since their inception. What has changed is the capability on the attacker’s side.

AI-powered cracking tools no longer rely on brute-force randomness. They study how people actually create passwords, patterns, shortcuts, and predictable choices. They know that roughly 60% of people capitalize the first letter and add a number at the end. They know that when a special character is required, it’s almost always an exclamation point placed last.12

People also tend to overshare. Identifiable information can be scraped from social media sites to assist AI in cracking the code. For example, that password someone built from their dog’s name, a capital letter, their birth year, and a trailing symbol. AI is specifically designed to predict exactly this structure. When challenged, this approach falls in seconds.

Compounding the problem, infostealer malware harvested 548 million passwords from infected devices in 2024 alone.13 Those stolen credentials circulate on criminal forums for roughly $10 each or through subscription services priced around $80 per week for a continuous feed of fresh credentials.11 It’s a mature market, and weak passwords are the raw material that keeps it running.

Why the Basics Keep Getting Overlooked

At Arcova, we see this pattern consistently. Organizations invest heavily in advanced security tools but haven’t audited or updated complexity requirements for their Active Directory passwords in years. Detection and response capabilities are strong. Password policies have not been updated since 2019.

Part of the issue is prioritization. Advanced threats are compelling. Password hygiene is not. Security leaders get recognized for deploying zero-trust architecture, not for blocking “123456” in the corporate directory.

Another factor is misplaced confidence in multi-factor authentication. MFA is critical, no question. But adoption remains inconsistent, and attackers have developed techniques to bypass it through stolen session cookies and token hijacking. MFA is a layer of defense, not permission to leave the first factor weak.

There is also a systems design problem. The average person manages roughly 100 online accounts. Without a password manager, which only about a third of people use, reuse becomes almost inevitable. The authentication model itself pushes people toward the behavior security teams are trying to prevent.

What Actually Moves the Needle

The solutions are not new. They are simply underprioritized.

Shift to passphrases over traditional complexity rules. NIST’s updated guidance recommends longer passphrases, fourteen characters or more, rather than the traditional mix of uppercase, lowercase, numbers, and symbols.14 A passphrase like “purple-giraffe-eating-tacos” is easier to remember and exponentially harder to crack than “P@ssw0rd!23.” The old approach created passwords that were difficult for people and predictable for machines. Passphrases reverse that equation.

Audit credentials against known breach databases. If a password has appeared in a previous breach, its complexity is irrelevant. It is already compromised. Automated checks against databases like Have I Been Pwned should be standard, not aspirational.15

Make password managers the organizational default. Not recommended. Not available upon request. Default. When the tool is provided and expected, the password reuse drops significantly.

Deploy MFA comprehensively and layer additional monitoring behind it. Watch for anomalous login behavior, stolen session tokens, and credential-based attack patterns. MFA is necessary, but it’s not sufficient on its own. Not all MFA is created equal. Phishing-resistant authentication and device trust are significantly stronger than SMS or email-based verification, which attackers have learned to exploit.

Finally, invest in security awareness that actually resonates. Tell people about the Louvre. Tell them about the $10 credential market. Show them how quickly AI dismantles the password they thought was clever. Specifics land harder than generic compliance training ever will.

How Arcova Approaches This

Arcova believes the fundamentals deserve the same strategic attention as advanced capabilities. Not because they are simple. Getting them right across an entire organization is genuinely difficult. But the most sophisticated security architecture is only as strong as the credentials beneath it.

We help organizations identify where real exposure lives. Often, it is not the threat landscape. It is the password policy that has not kept pace, MFA gaps that haven’t been mapped, or credential hygiene that lost priority as budget shifted toward more visible investments.

Advanced threats require advanced defenses. But no amount of AI-powered detection matters if an attacker can walk through the front door using “Admin1234.”

The Bottom Line

The industry focuses heavily on what’s next, quantum threats, agentic AI, and supply chain risk. All of it is real. All of it is important.

But nearly half of breaches still begin with a compromised credential. The most popular password on earth gets cracked instantly. And billions of stolen credentials sit on criminal marketplaces, available for less than the price of a coffee.

Before pursuing the next frontier, it is worth asking a more immediate question. Does anyone in the organization still have “Company123” as their password? Because attackers are already checking. And AI is helping them find the answer faster than ever.

Arcova can help make sure that answer is no.

Contact Arcova to assess credential security, close MFA gaps, and build programs that get the fundamentals right alongside advanced defenses. The strongest security strategy starts with the basics.


Sources

  1. NordPass, “Top 200 Most Common Passwords 2024,” November 2024. https://nordpass.com/most-common-passwords-list/
  2. ESET/WeLiveSecurity, “Old habits die hard: 2025’s most common passwords were as predictable as ever.” https://www.welivesecurity.com/en/cybersecurity/old-habits-die-hard-2025-most-common-passwords/
  3. Comparitech, “‘Minecraft’, ‘qwerty’, and ‘India@123’ among 2025’s most common passwords: report,” November 2025. https://www.comparitech.com/news/minecraft-qwerty-and-india123-among-2025s-most-common-passwords-report/
  4. CyberNews analysis of breached credential databases, 2024. Referenced in Heimdal Security, “Password Breach Statistics in 2026.” https://heimdalsecurity.com/blog/password-breach-statistics/
  5. DeepStrike, “70+ Password Statistics for 2026.” https://deepstrike.io/blog/password-statistics-2025
  6. Verizon, 2025 Data Breach Investigations Report (DBIR). Referenced in Heimdal Security, “Password Breach Statistics in 2026.” https://heimdalsecurity.com/blog/password-breach-statistics/
  7. DemandSage, “35 Password Statistics 2026 – Data Breaches & Industry Report.” https://www.demandsage.com/password-statistics/
  8. ABC News, “Password to Louvre’s video surveillance system was ‘Louvre,’ according to employee,” November 6, 2025. https://abcnews.com/International/password-louvres-video-surveillance-system-louvre-employee/story?id=127236297
  9. Kaspersky Blog, “Breach of 120,000 IP cameras in South Korea,” December 11, 2025. https://www.kaspersky.com/blog/south-korea-120000-ip-cameras-hacked/54961/
  10. HackManac, “Is Your Password Policy Ready For 2026?” December 11, 2025. https://hackmanac.com/news/is-your-password-policy-ready-for-2026
  11. Heimdal Security, “Password Breach Statistics in 2026.” https://heimdalsecurity.com/blog/password-breach-statistics/
  12. Spacelift, “70+ Password Statistics for 2026.” https://spacelift.io/blog/password-statistics
  13. DeepStrike, “70+ Password Statistics for 2026”: infostealer malware lifted 548 million passwords and 17 billion session cookies from infected devices in 2024. https://deepstrike.io/blog/password-statistics-2025
  14. NIST Special Publication 800-63B, Digital Identity Guidelines: Authentication and Lifecycle Management. Referenced in Specops Software, “Top 5 insights on modern password security as we head into 2026.” https://specopssoft.com/blog/top-5-password-security-insights-2026/
  15. Have I Been Pwned: https://haveibeenpwned.com/

Ready to advance your business goals?

Let's discuss how we can protect your enterprise.

Contact Us