“password”, “passw0rd” and “password1” remain popular choices…
According to ImmuniWeb, there are currently over 21 million (21,040,296) stolen user credentials belonging to Fortune 500 companies available on the Dark Web – over 16 million (16,055,871) of which were compromised in the last 12 months.
A whopping 95 percent of the credentials included unencrypted, or already bruteforced and hacked by attackers, plaintext passwords, the company says.
(More than half of the publicly available data is “outdated or fake, or simply comes from historical breaches under false pretenses about newly compromised files,” he notes, though that may prove to be little consolation to the security teams at the companies in question.).
Switzerland-based ImmuniWeb scours various Internet, Pastebin, IRC channels, social networks, message boards, etc. on the TORto uncover details about the rise of the credential market. (Stolen credentials can be used to attack networks, with initial access used to escalate privileges.)

Technology, Energy, Financial Services are more exposed
Among the revelations in today's report: the password "password" (which is considered extremely strong) remains extremely popular with users, along with cunning and unexpected twists like "passw0rd" and "password1."
The technology, financial services, and energy sectors are the three largest industries with the highest volume of credentials exposed, as 42% of stolen passwords “are somehow related to the victim’s business name or the offending resource in question, effective.”
Password bruteforcing tools are widely available online, where they are used by both penetration researchers and black hat hackers.
(As users' computing power increases, the speed at which even encrypted passwords can be cracked is increasing rapidly, as February's Hashcat revealed.).
(Hackers never lock accounts, since they typically don't attempt to guess a password on the login page of live accounts. Instead, they typically purchase a file of user IDs and password hashes: an attempted exploit in this scenario involves using such tools to find the equivalent numerical representation of that hash to reveal the password .)
Stolen user credentials: The most popular passwords
Ilia Kolochenko, CEO and Founder of ImmuniWeb, said: “These numbers are both disappointing and worrying. Cybercriminals are smart and pragmatic, focusing on the quickest, cheapest and safest way to obtain your credentials.
“The vast wealth of stolen credentials accessible on the Dark Web is a modern-day Klondike for hackers who don’t even need to invest in expensive 0-day or time-consuming APTs. With some persistence, they can easily bypass security systems and grab what they want.
There were only 4.9 million (4,957,093) fully unique passwords within the 21 million records the company identified, suggesting that many users are using identical or similar passwords. It recommends using an Attack Surface Management (ASM) solution to map risk, implementing an password that enforces the integrity of internal and third-party systems, and always using two-factor authentication (2FA) on critical systems.
