Thousands of IT administrators are using ‘admin’ as their default password (2024)

Thousands of IT administrators are using ‘admin’ as their default password (1)

IT administrators can be just as lax at password security as end-users, according to new research.

Analysis of over 1.8 million admin credentials by Outpost24 found that basic default passwords were used frequently by IT staff, with highly predictable terms used tens of thousands of times.

The study found that the term “admin” ranked among the most popular passwords among IT administrators with over 40,000 entries.

Of the top 20 administrator passwords analyzed by the firm, basic numeric combinations such as ‘123456’ and ‘12345678’ were also highlighted among the most-used by admins.

Similarly, terms such as ‘admin123’ and ‘Password’ were also common.

The research points to a culture of poor password security and management that could be placing thousands of organizations worldwide at risk of compromise, according to Outpost24.

Thousands of IT administrators are using ‘admin’ as their default password (2)

Google passkeys now default for users in shift away from traditional authenticationHow do hackers get your passwords?Are password managers safe? Here’s how to use them

Passwords observed in use by the cyber security firm were obtained from credential stealing malware, which is frequently used to compromise user accounts.

Get the ITPro. daily newsletter

Receive our latest news, industry updates, featured resources and more. Sign up today to receive our FREE report on AI cyber crime & security - newly updated for 2024.

These specific passwords, however, could be easily guessed without the need for sophisticated techniques, underlining the potential danger many organizations face by not employing stringent password security practices.

“While the data from our analysis was obtained from credential stealer software, a type of malware designed to target the applications capable of storing usernames, passwords, and other authentication credentials, most of the passwords in our list could have been easily guessed in a rather unsophisticated password-guessing attack,” the firm said.

Inadequate password security

Poor password security has the potential to create significant risks for organizations of all sizes, and the issue of hygiene and best-practice has been a recurring topic in recent years.

A recent study from Authlogics, a provider of password security technologies, warned that the volume of exposed account passwords has skyrocketed.

The firm said its Password Breach Database reached a highly concerning landmark in March 2023, surpassing five billion compromised account credentials.

Separate research from SpyCloud this year also shed light on the scale of the issue. The threat intelligence firm said that password reuse and substandard login credentials remain a “rampant” issue globally.

RELATED RESOURCE

Thousands of IT administrators are using ‘admin’ as their default password (3)

Find out how to use event log data from your SIEM platform to make IT and business decisions

DOWNLOAD NOW

Outpost24 stressed that administrators and end-users alike should never use default login credentials and always create a “long, strong, password” for each individual account.

“Enforce these security measures across your network,” the firm said, adding that organizations should always be conscious of the telltale signs of poor password security practices.

William Wright, CEO of Closed Door Security told ITPro that passwords should neither be shared nor in a basic format.

“These are rookie mistakes, but they still happen every single day, and criminals are fully aware of it,” he said.

“When criminals target an organization, they understand one valid credential is all they need to execute a data breach or install ransomware. So, when organizations are using ‘admin’ on their administrator accounts this gives them all the access they need, which means it’s the first attack path they will test.”

Thousands of IT administrators are using ‘admin’ as their default password (4)

Ross Kelly

News and Analysis Editor

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.

He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.

For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.

More about security

In the age of AI threats, the future of security is unifiedNCA takes down world’s most prolific DDoS-for-hire website

Latest

Meta’s Llama 3.1 promises to compete with closed source competition
See more latest►

Most Popular
Transparency is “vital” in big tech’s new coalition on AI safety, experts suggest
Google DeepMind's chief scientist says AI energy use not as bad as it looks
Where will the next democratic presidential nominee stand on tech policy?
OpenAI dropped from AI copyright lawsuit
Digital Catapult launches platform to solve supply chain setbacks
UK police arrest teen in connection with MGM Resorts hack
DDoS attacks have doubled so far in 2024
Security and compliance concerns are driving the shift to hybrid cloud
CISA breached a federal agency as part of its red team program — and nobody noticed for five months
Manchester named as UK's most 'AI-ready' city

Snowflake’s vision to be Netflix not YouTube serves up more watchable content for customers
Thousands of IT administrators are using ‘admin’ as their default password (2024)
Top Articles
Latest Posts
Article information

Author: Moshe Kshlerin

Last Updated:

Views: 6623

Rating: 4.7 / 5 (57 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Moshe Kshlerin

Birthday: 1994-01-25

Address: Suite 609 315 Lupita Unions, Ronnieburgh, MI 62697

Phone: +2424755286529

Job: District Education Designer

Hobby: Yoga, Gunsmithing, Singing, 3D printing, Nordic skating, Soapmaking, Juggling

Introduction: My name is Moshe Kshlerin, I am a gleaming, attractive, outstanding, pleasant, delightful, outstanding, famous person who loves writing and wants to share my knowledge and understanding with you.