Security Advisory on Most Commonly Used Passwords in Nigeria

Risk:
high
Damage:
high
Platform(s):
Systems Networks Mobile Networks and Telephones
Advisory ID:
ngCERT-2022-0101
Version:
N/A
CVE:
N/A
Published:
December 9, 2022

Summary


A recent research by Nordpass and a group of independent researchers has revealed the 200 most common passwords in 2022. The methodology used also allowed them to collect information based on country and gender. Discovery suggests that a lot of people around the world do not adhere to password hygiene rules.

Description & Consequence


Nordpass and independent researchers who specialize in cybersecurity incidents combed through a 3TB database to compile the list of passwords. The researchers had to divide the data into several verticals in order to conduct a statistical analysis focused on countries and gender. The top three most commonly used passwords in Nigeria are 123456, 1982 and 12345678 – all of which will take a moderately-skilled hacker less than a second to compromise. The table below shows the top 10 most commonly used passwords in Nigeria and in all the 30 countries whose data was available.

S/N

Nigeria

All Countries

1.

123456

password

2.

1982

123456

3.

12345678

123456789

4.

12345

guest

5.

1234567

qwerty

6.

123456789

12345678

7.

1234

111111

8.

36874399

12345

9.

000000

col123456

10.

Abdul44@

123123

 

For the complete list and the period it will take to crack them, check the link below.

A weak password makes it easier for an attacker to gain access to one's account. For example, if an attacker gains access to a person's banking app, the attacker can steal money from the account. If it's their social media account, the attacker can impersonate them and ask their contacts for money, or even lock them out of the account by changing the email address or password. If the attacker gains access to the victim's email account, he or she will have access to personal information. If the compromised account is linked to a work account, it can be used to phish coworkers or even launch a business email compromise (BEC) attack. 

Solution


It is important to strictly observe healthy password hygiene. This can done by:

  1. Creating a password that’s long, complex and unpredictable. This means the password should be at least 12 characters long, be a combination of letters (both uppercase and lowercase), numbers and special characters (symbols), and something that’s not easily guessed.
  2. The same password should not be reused across accounts; so if you’re using a particular password for your Facebook account, make sure you use a different one for your banking application, because once one account becomes compromised it means the attacker cannot use the same password to compromise your other accounts.
  3. Change passwords periodically.
  4. To simply the processes above, use a password manager.

Reference


Revision


Related Articles