August 14, 2026
You’re Still Using Your Dog’s Name + ‘123’ (And Hackers Know It)
We live in 21st century, yet our password creativity is still stuck in the stone age.

By Sulashee Batapola
1 min read
When creating a new account, most of us just type our emails and throw in the very first word that pops into our head as the password. What are the chances that word is a randomly generated string like FJBjjw&jvjd*24 or Ety125fhufyg& Very low. What are the chances it's qwerty, password123, or brownie123? Embarrassingly high.
Look, no need to lie…we all love our pets but that doesn't mean their names should belong in our security settings in the most predictable way possible. Let's say you love your dog, Brownie, what's your idea of a clever password? brownie123? no, lets make it a little more complex by using B instead of b? yeah…that's not going to protect anything.
Hackers use a wide variety of tools, and simple tactics like password spraying will easily do the trick. They'd blast hundreds of accounts with the most obvious passwords and voilà….you're a compromised.
We love to convince ourselves, "It's fine, my password is so simple, so i can actually remember it" , but then we are missing the whole point of a password. Passwords exist to protect our digital identity, simplicity should be the very last thing on our minds.
So, when are we going to change?
Probably not anytime soon until we realize how actually bad the problem is.
The main reason we stay reckless is the little lie we tell ourselves "why would anyone hack me. I'm not rich, famous, or running a fortune 500 company".
Here is the cold, harsh truth about modern cybercrime activities: Hackers don't care who you are.
They aren't sitting in a dark room manually guessing brownie123 on your personal instagram account while wearing a hoodie. They simply don't have to. Today's most of cybercrime activities are fully systemized with scripts and tools. They tests thousands of major platforms in the internet within seconds to find a vulnerability of them.
When a sketchy little e-commerce store you bought a t-shirt from back in 2021 suffers a data breach, your go-to email and brownie123 password don't just stay there. They get packaged into massive text files, dumped on forums, and fed directly into automated botnets.
This process known as credential stuffing doesn't target you specifically. It targets your predictability. If you re-used that same brownie123 password for your main email, your Amazon account, or your streaming services, you didn't just leak one account. You handed over the keys to your entire digital identity.
So the real problem isn't just that our passwords are predictable. It's that we treat them like a minor inconvenience rather than our first line of defense.