Over 42.5 million data breaches linked to weak passwords, exposing major cybersecurity gaps.
A new report from Preply has revealed that “123456” is the most commonly cracked password in Singapore, appearing in over 42.5 million data breaches. Despite its simplicity, this password remains one of the easiest targets for cybercriminals, taking less than a second to crack. The findings highlight the urgent need for stronger password practices amid rising cybersecurity threats.
In light of growing cybersecurity threats globally, Singapore faces significant risks due to weak password habits. The latest data breach incidents, including the LingoAce case, underscore vulnerabilities that companies and individuals face when failing to adopt strong password protocols.
“123456” Tops the List of Breached Passwords
The report highlights that “123456” has been involved in over 42.5 million breaches in Singapore alone. This simple sequence can be cracked in less than a second, making it a prime target for cybercriminals.
Other Commonly Compromised Passwords
Besides “123456,” several other weak passwords were frequently breached:
– “123456789” – 18.3 million breaches
– “qwerty” – 10.7 million breaches
– “password” – 10.4 million breaches
– “12345678” – 6.9 million breaches
– “111111” – 5.07 million breaches
These passwords share a common flaw: predictability, which is exploited by hackers through brute-force attacks.

Short Passwords Are the Weakest Link
The analysis reveals that 96% of the most breached passwords contain fewer than 10 characters, highlighting the importance of longer, more complex combinations to enhance digital security.
Real-World Consequences: The LingoAce Data Breach
In 2023, Singapore’s Personal Data Protection Commission (PDPC) fined edtech company LingoAce SGD 74,000 after a breach compromised the data of 557,000 users. The breach was traced to a weak administrator password: “lingoace213”, which exposed the company to cyber threats.
The Growing Threat of AI-Driven Password Cracking
The rise of artificial intelligence (AI) poses new risks. According to Singapore’s Cyber Security Agency, AI-driven tools can crack over 50% of common passwords in under 60 seconds. These tools automate brute-force attacks, testing thousands of password combinations with unprecedented speed.
Tips for Creating Stronger Passwords
Preply recommends the following strategies to enhance password security:
1. Avoid predictable sequences: Skip basic patterns like “123456” or “password.”
2. Use random words: Combine unrelated words with special characters and unexpected capitalisation.
3. Longer is stronger: Aim for passwords with at least 10 characters.
4. Incorporate different languages: Use words from various languages or dialects to reduce predictability.
Language expert Yolanda Del Peso adds, “Password-cracking tools often rely on word lists from popular languages. Using characters from different languages makes passwords less predictable.” However, she cautions users to ensure compatibility across devices.
This report serves as a stark reminder of the importance of cybersecurity hygiene. The rise of AI-driven password attacks means that relying on simple passwords is no longer safe. Strong, unique passwords are the first line of defence in protecting personal and corporate data.
Sources: The Independent SG, HRD Asia (2025)
Keywords: Singapore Password Breaches, Cybersecurity Threats, Weak Password Risks, AI Cyber Attacks, Data Protection Breach, Strong Password Tips, Password Vulnerabilities, Cybercrime in Singapore, AI Password Cracking, LingoAce Data Leak











