The Most Common Password Is Still 123456. Here Is What Actually Fixes That.

A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Photoreal news-editorial 16:9 image of a single smartphone lying flat on a plain concrete desk, its screen glowing with a generic six-digit authentication code
Share

Key points

  • The most common password in the United States is still 123456, according to the Cybersecurity and Infrastructure Security Agency (CISA), the US government's main cyber watchdog.
  • CISA states that accounts protected by multi-factor authentication (MFA) are 99 percent less likely to be broken into than those protected by a password alone.
  • A former chief information security officer (CISO) at Hyatt Hotels and United Airlines argues that foundational security steps, led by MFA, matter more than any new technology.
  • Passkeys, a newer login method that replaces passwords with a cryptographic key stored on your device, are now available on most major platforms and go one step further than standard MFA.

The headline number is almost embarrassing: 123456 is still the country's most popular password. Not a variation of it. The actual string. Six digits in order.

That single fact sits at the top of CISA's guidance on multi-factor authentication, and it explains why the agency keeps pushing one message above all others.

What is multi-factor authentication, and why does it matter so much?

MFA means you prove who you are in two or more ways before you get in, not just one. Think of it like a door that needs both a key and a PIN: if a thief steals your key, the PIN still stops them.

In practice, that second factor is usually a six-digit code sent to your phone, a prompt in an app, or a fingerprint scan. A stolen password alone is no longer enough to break in.

CISA's own figure is stark: accounts with MFA enabled are 99 percent less likely to be compromised. That's not a vendor's marketing claim; it's the position of the US government's own cyber agency.

Millions of accounts, personal and corporate, still rely on a password alone despite that.

What does an expert who has run security at major companies say?

Writing in CSO Online, a longtime CISO who led security at Hyatt Hotels and United Airlines argues that the security industry has a spending problem. Companies cycle through expensive new products every quarter looking for a technical fix, when the fixes that actually work are the ones that have existed for years.

His point: new tools only help once you've got the basics right. MFA is the clearest example. It's not exciting. No conference demo required. It just works.

He also recommends passkeys. A passkey stores a unique cryptographic key on your phone or computer, so you never type a password at all; a fingerprint or face scan is what opens it. It's harder to steal than a password and harder to intercept than a text-message code. All the major platform vendors support passkeys today. Worth noting, though: our 4 September story "Passkeys Aren't Magic: Researchers Map 39 Ways to Sidestep Them" found that attackers don't need to break the cryptography; they walk around it instead.

The practical sequence he describes for any organisation:

  1. Know what devices and accounts you actually have (you can't protect what you can't see).
  2. Turn on MFA everywhere, then move toward passkeys where you can.
  3. Know what your most important data is, and protect that first.
  4. Have a recovery plan, not just a prevention plan, and practise it.

What should ordinary people do right now?

If your bank, email, or social media account offers MFA, turn it on today. The setting is usually under "Security" or "Privacy" in your account options. An app-based code is stronger than a text message, though a text message is still far better than nothing.

If a site offers passkeys, the two-minute setup is worth it.

Change 123456 while you're at it.

Here's what years on this beat tell me: MFA is the one control where the evidence is overwhelming and the barrier to adoption is almost nothing. The gap between how effective it is and how widely it's actually switched on remains, bafflingly, enormous. That gap is the real story, not whatever new tool a vendor announced this week.

© 2026 Threat Vectr