Change Your PIN Code Now If It’s On This List

Posted by Davey Winder, Senior Contributor | 2 weeks ago | /consumer-tech, /cybersecurity, /innovation, Consumer Tech, Cybersecurity, Innovation, standard | Views: 46


Update, May 26, 2025: This story, originally published May 24, has been updated with a brief history of PIN codes, information regarding the most secure codes you can use and why 8068 really isn’t the safest number despite the claims of some security experts. It also now contains a list of passwords that must be avoided at all costs.

Passwords are under attack, that’s a given. Whether it’s from initial access malware looking to open up networks for ransomware attacks, public databases containing hundreds of millions of stolen plaintext credentials, or state-sponsored threat actors with spying on their minds. Nobody can say they are unaware of the dangers of weak or reused passwords, but what about your PIN code? Yes, those four digits that are used when unlocking your smartphone and all the valuable data it provides instant access to. OK, so you might argue that you use your fingerprint or face to unlock your Android or iPhone, which is fair enough, apart from when there’s been an update, reset, or something goes wrong and you have to resort to your PIN after all. What if there were a list of 50 PIN codes that should, under no circumstances, be used? Read on.

ForbesThis Code Can Stop iPhone And Android AI Hack Attacks — Act Now

Do Not Use These 50 PIN codes

PIN codes are not, let’s face it, the most secure means of restricting access to your valuable smartphone. Yet they are used to lock your SIM card and the device itself. They underpin, if you’ll excuse the pun, the biometrics that you rely upon to gain quick and safe access to your iPhone or Android when you are out and about, and are required under certain circumstances, whether you have fingerprint or facial recognition enabled or not. I mean, do the math, and you’ll learn that a four-digit PIN “only” requires 10,000 attempts at the most in order to crack it, if you include 0000 and 9999. That’s still a lot of faffing around, of course, and there are far easier and much quicker ways to crack certain PIN codes. And that, dear reader, is where the danger list comes in.

When it comes to advice about choosing a PIN code for your smartphone, if you want to prevent friends and family, even work colleagues, from being able to take a quick look at your stuff when you pop to the toilet without it, it’s best to avoid birthdays and anniversaries. That’s another given. But what if they could have a really good chance of cracking what appears, to you and many others at least, like a random code that has no obvious personal connection?

ForbesChange Your Password Now If It’s On This List

An analysis of more than 29 million PIN codes that turned up in data breach lists, discovered that one in ten people used the same four numbers. That analysis produced a list of the top 50 PIN codes found, and as such, these are the ones used by most people and so the ones to avoid. After all, if I can find this list, so can smartphone thieves.

Here’s the list of 50 PIN codes you should never use.

  1. 0000
  2. 1010
  3. 1111
  4. 1122
  5. 1212
  6. 1234
  7. 1313
  8. 1342
  9. 1973
  10. 1974
  11. 1975
  12. 1976
  13. 1977
  14. 1978
  15. 1979
  16. 1980
  17. 1981
  18. 1982
  19. 1983
  20. 1984
  21. 1985
  22. 1986
  23. 1987
  24. 1988
  25. 1989
  26. 1990
  27. 1991
  28. 1992
  29. 1993
  30. 1994
  31. 1995
  32. 1996
  33. 1998
  34. 2000
  35. 2002
  36. 2004
  37. 2005
  38. 2020
  39. 2222
  40. 2468
  41. 2580
  42. 3333
  43. 4321
  44. 4444
  45. 5555
  46. 6666
  47. 6969
  48. 7777
  49. 8888
  50. 9999

I sorted the list into numerical order to make it easier to check to see if you were using a dangerous PIN, but here are the top ten by most-used code numbers:

  1. 1234
  2. 1111
  3. 0000
  4. 1342
  5. 1212
  6. 2222
  7. 4444
  8. 1122
  9. 1986
  10. 2020

ForbesMillions Of Stolen Passwords For Sale To Hackers For Just $81

A Brief History Of The PIN Code

The invention of the Personal Identification Number is most commonly attributed to James Goodfellow, who patented the technology alongside his other hugely influential creation, the Automated Teller Machine, in 1966. The first ATM in use was installed in London by Barclays Bank in 1967, while the first PIN code security measure for bank cards had to wait until 1972 when Lloyds Bank introduced them with information-encoding magnetic strips on and a PIN code for added security. The history of the PIN in security gets a little complicated, as there was another patent, in 1972, filed by Mohamed M. Atalla for a PIN verification system using a hardware security module. The so-called Atalia Box, which was launched commercially in 1973, as a product called the Identikey, was the first card reader ID system with a PIN that would go on to replace the need for signatures. For this reason, and somewhat confusingly, Atalla is often referred to as the father of the PIN.

Not Just PIN Codes – Add These Passwords To The Never Use List

It would be remiss of me not to share details of the password lists you need to check your credentials against, as a matter of some urgency, as well as the already mentioned PIN codes. A combination of research into the most commonly used passwords that have been found in data breach databases for personal and enterprise use, as well as being analyzed on a geographical basis, has produced a list of dangerous passwords to avoid. I have further combined these lists here for ease of accessibility, but head for the original article to get the full picture.

  1. 000000
  2. 111111
  3. 11111111
  4. 121212
  5. 123123
  6. 12345
  7. 123456
  8. 1234567
  9. 12345678
  10. 123456789
  11. 1234567890
  12. 555666
  13. aaron431
  14. abc123
  15. abcd1234
  16. ABCDEF
  17. admin
  18. charlie
  19. dragon
  20. iloveyou
  21. lemonfish
  22. liverpool
  23. monkey
  24. password
  25. password1
  26. qwerty
  27. qwerty1
  28. qwerty123
  29. secret
  30. tangkai
  31. user0123
  32. welcome
  33. woaini

What Are The Most Secure PIN Codes To Use In 2025?

Let’s start by saying that 2025 certainly isn’t on my list of safest PIN codes as it breaks the don’t use a date golden rule. If we discount not only using the same four digits, which the dangerous list has proven to be a big no-no, but also repeating any digits at all, at least when it comes to a four-digit PIN code, and more on that in a moment, then the choices start to narrow somewhat. The number of permutations where the digits do not repeat within the code itself is 5040 if Professor Google and a calculator have not let me down. This allows for both 0123 and 0321 to be different codes, as no digits repeat within each separate PIN. That has already all but halved the number of codes available to choose from, a good start. Back in 2012, a study of stolen credentials determined that the least popular, and so by definition the safest, PIN code was 8068. To this very day I have seen this still being quoted as a fact, or at least a statistical fact, but, of course, wearing my hacker hat I can tell you that’s very wrong indeed. As soon as 8068 was named online, it became anything but safe. As soon as you could Google what’s the safest PIN code and get 8068 returned, it became a very weak number instead. The same applies to the other numbers noted in the study, 6835, 7637, 8093, and 9629.

So, what are the most secure PIN codes to use in 2025? Random is always best, unless you are choosing from a very small base pool to begin with, as is the case with four-digit PIN numbers. The answer to the question, therefore, is to increase the pool and increase the odds in your favor. To do this, simply stop using four-digit PINs altogether and start using sixt-digit ones, or better yet in my never humble opinion, ten-digits. Interestingly, there’s an international standard for PIN code management in financial services, ISO 9564-1, and this allows for PINs of up to 12 digits. However, it recommends six as being the longest deployment for reasons of usability. This is why many online services and apps require a six-digit PIN as a backup user verification method rather than the more common four-digit ones we see employed on lock screens. The longer it is, the harder it is to guess, assuming that the same basic principles of PIN code construction apply.

To do this, opt to use a password instead of a PIN number to lock your phone, and just employ numbers instead of characters. You can then have a custom-made PIN code that is both much harder to guess or crack, while remaining easy enough to remember. My smartphones are protected by ten-digit PINs using just this method and I have never looked back.

ForbesChrome Password Update For 3 Billion Google Browser Users



Forbes

Leave a Reply

Your email address will not be published. Required fields are marked *