Quartz
Subscribe
Quartz
Subscribe
Edition
Business News
A.I.
Technology
Money & Markets
Leadership
Lifestyle
Latest

Get Quartz in your inbox

Free daily briefing on global business news.

Business News
AirlinesAutomobilesFoodPharmaceuticalsPolitics & GovernmentRetail & EcommerceSpace & AerospaceEarnings
Technology
A.I.ComputingConsumer TechSpace & AerospaceEarnings
Money & Markets
Economic IndicatorsMarketsPersonal FinanceEarnings
Lifestyle
Cars & BikesCollectingEntertainmentFood & Fine DiningHealth and FitnessReal EstateTravel
Quartz

Global business news for a smarter world

Topics

  • Business News
  • Money & Markets
  • Tech & Innovation
  • Generation A.I.
  • Lifestyle
  • Leadership

Products

  • Daily Brief
  • Weekly Digest
  • Member Benefits
  • Quartz Pro

Legal

  • Sitemap
  • About
  • Accessibility
  • Privacy
  • Terms of Service
  • Advertising

© 2026 Quartz Media, Inc. All rights reserved.

Cybersecurity

Millions of stolen Last.fm passwords have been decrypted. These are the top 50

Remembering a strong password is difficult. That’s why people keep using passwords like “123456,” “password,” and more puzzlingly, “monkey.”

By Joshua Wong·1 min read·Updated July 21, 2022
Add QZ to Google

Remembering a strong password is difficult. That’s why people keep using passwords like “123456,” “password,” and more puzzlingly, “monkey.”

Those are some of the most popular passwords from a stash of data stolen from the music-streaming platform Last.fm in 2012. Hundreds of thousands of people used those three passwords to log in to their Last.fm accounts. The passwords were decrypted by LeakedSource, which maintains a collection of publicly available hacked data.

Daily Brief

The essential business news, delivered fresh every morning.

Join 500,000+ readers who start their day with Quartz.

By subscribing, you agree to our Terms of Service and Privacy Policy.

These are the 50 most frequently used passwords from the hacked stash of 43.6 million, according to LeakedSource:

LeakedSource says the hack took place on March 22, 2012 and includes information like each account’s username, e-mail address, join date and other data. It verified that the data were authentic by checking with a known user whose credentials were in the stash.

Even if many some of those users are no longer active on last.fm, the common (and bad) habit of reusing passwords means hackers might use the leaked data to break into people’s accounts on other services.

Last.fm had 49 million registered users at the time of the hack, according to one estimate. The company reported 55 million registered users in 2014, although only a fraction of those are likely to be active users. Last.fm was a pioneer of music streaming, and CBS acquired it for $280 million in 2007. Its parent failed to capitalize on its head start, however, and its user growth has stagnated over the years, even as losses have mounted and staff have dwindled. Spotify $SPOT was launched the October after the acquisition.