Common Password Mistakes That Put Your Online Accounts at Risk

Passwords are among the oldest parts of our digital lives, yet many people still protect important accounts with surprisingly predictable combinations. A pet's name, a birthday, a favourite football team or the same password used everywhere can seem convenient until one account is compromised. The problem has become more serious as people now use online accounts for banking, shopping, work, healthcare, social media and personal communication. Cybersecurity experts increasingly argue that password security is not simply about adding a symbol or changing one letter. Length, uniqueness, password managers and multi-factor authentication all matter. Some traditional password advice, meanwhile, is no longer considered particularly useful.
Hero Image


Reusing the Same Password Everywhere

One of the most dangerous password mistakes is using the same password for multiple accounts. It is easy to understand why people do it. Remembering dozens of unique passwords is difficult, particularly when every website seems to have different rules.

But a password exposed in one data breach can potentially be tried against other services. This technique, known as credential stuffing, takes advantage of password reuse. NIST specifically warns that using the same password across websites means a breach at one service could put other accounts at risk.


Choosing Personal Information

Using a birthday, family member's name, pet's name or favourite sports team may feel memorable, but such information can sometimes be discovered through social media or other public sources.

Attackers do not necessarily begin by randomly guessing millions of combinations. They often start with information that is likely to have been used by real people. NIST recommends avoiding personal information that could be guessed or inferred.


Making Small Changes to an Old Password

Another common mistake is believing that changing "Password123" to "Password123!" makes it dramatically safer.

Modern password guidance has moved away from complicated composition rules as the main measure of security. NIST notes that people often respond to such requirements with predictable substitutions, creating passwords such as adding a number or symbol to a familiar word. Longer passwords and passphrases are generally more useful.

Using Short Passwords

Length matters considerably. NIST's current digital identity guidance requires passwords used as a single authentication factor to be at least 15 characters long, while encouraging services to allow much longer passwords.

A memorable passphrase made from several unrelated words can therefore be more practical than a short, complicated-looking password.


Writing Passwords in Unsafe Places

Keeping passwords on a scrap of paper beside your computer or in an easily accessible phone note can create another security problem.

A password manager offers a safer alternative by generating and storing unique credentials, reducing the need to memorise dozens of passwords. CISA recommends password managers precisely because remembering many long, unique passwords is unrealistic for most people.

Ignoring Multi-Factor Authentication

Even a strong password is not an impenetrable barrier. Phishing can trick people into revealing credentials, while stolen passwords can circulate after data breaches.

Multi-factor authentication adds another layer by requiring an additional method of verification. NIST and CISA both recommend using MFA wherever it is available.

Passkeys are also emerging as an alternative to traditional passwords. They use cryptographic credentials stored on a device and can be unlocked using methods such as a fingerprint, face recognition or device PIN.


Changing Passwords Constantly Without a Reason

Interestingly, one piece of traditional advice has changed. NIST's current guidance says services should not routinely force users to change passwords unless there is evidence that the password has been compromised.

Constantly changing a password can encourage predictable variations rather than genuinely new credentials.