A compelling case to change all those finance passwords pronto
You know what makes a bad password: 12345, 11111 or even password itself! But there’s new research on the passwords that get hacked the most often. And they’re different from the usual suspects.
More importantly: This new list offers some new insight into how your people may be picking codes that lead hackers right into your company’s sensitive systems.
Check out what they discovered so you can feel confident none of your staffers are leaning on these predictable patterns when they set their safeguards.
The not-so-great 8
A security organization in the UK analyzed which passwords were most often involved in a data breach.
Here are the eight that are more likely to open the door to cyber-crooks and that you want staffers to scrub from their rotation:
- blink182
- liverpool
- superman
- manutd
- ashley
- michael
- cowboys1, and
- iloveyou.
While this data was collected in the UK, it highlights a trend as far as what people tend to pick:
- sports teams
- musicians, and
- fictional characters.
Those are categories you want to steer employees away from when creating their passwords. Because if they can think of them, so can crooks!
And there’s more reason than ever to embrace some next-level passwords.
Earlier this year the largest personal data breach in history hit. It captured:
- 772.9 million emails
- 21.2 million passwords, and
- 1.1 billion unique combinations of email addresses and passwords.
“Collection #1” attacked personal records, but if employees use the same passwords for multiple accounts, including work ones – and many folks do! – you could have been vulnerable. Plus, some folks still share their passwords with their co-workers.
They’ll keep trying ‘til they get in
Hackers can use the stolen email and password combinations to test them across all online accounts with a technique known as “credential stuffing.”
How it works: Thieves (often via botnets) keep trying every stolen email/password combo until they can get in to a system.
Whether or not any of your people were hit by Collection #1, there’s a very valuable lesson: Have every employee immediately change any company system password that they also use on a personal account.
Free Training & Resources
White Papers
Provided by Personify Health
White Papers
Provided by Anaplan
Further Reading
A big reason employers are still allowing hybrid work is business benefits like reduced operating costs. But it’s also harder to ensu...
Companies say they’re struggling to find talent. Maybe you’re in the same boat. It can seem like top performers are choosing ot...
Productivity is essential to every finance professional. But being productive isn’t always easy when you’re pulled in many dire...
In a matter of months, companies will possess first-ever guidelines for environmental credit accounting. Public and private firms will be r...
If your company’s employees are like most, they’d score a big fat F on a financial literacy test. Every year, the Teachers ...
Some people naturally want confrontation. It’s just how they roll. And most leaders want to avoid confrontation — especially in ...