The list of passwords was compiled in partnership with independent researchers specializing in researching cybersecurity incidents. They evaluated a 4.3TB database extracted from various publicly available sources, including those on the dark web. No personal data was acquired or purchased by NordPass to conduct this study.

Researchers classified the data into various verticals, which allowed them to perform a statistical analysis based on countries. NordPass exclusively received only statistical information from the researchers, which gives no reference to internet users’ personal data.

NordPass, in partnership with third-party researchers, analyzed passwords from a 6.6TB database. These passwords were stolen by various stealer malware, such as Redline, Vidar, Taurus, Raccoon, Azorult, and Cryptbot. Malware logs include not only passwords, but also the source website. Researchers categorized the most popular passwords per platform type and shared statistically aggregated findings with NordPass.


of all web app attacks use stolen credentials

Source: Verizon


of the most common items for sale on the dark web are online accounts, emails, and passwords.



Credentials have been breached since 2016



is the number of passwords that an average user has.

Source: NordPass

Use complex passwords

Your password should be at least 20 characters long and include a mix of uppercase and lowercase letters, numbers, and special symbols. Avoid using easily guessable information like birthdays, names, or common words.

Never reuse passwords

Never use the same password across multiple sites or services. If one account gets compromised, all your accounts could be at risk.

Check your passwords

Take the time to regularly assess your password health. Identify weak, old, or reused passwords and improve with new and complex ones for a safer online experience.

Use a password manager

Generate and store complex and unique passwords for each of your accounts with the help of NordPass. These tools can generate, retrieve, and store complex passwords for you.

