Skip to main content
Back to blog
Cybersecurity
August 8, 2026•The Solutions MC Team

The Password '12345': Why Your Data Is at Risk

The password “12345”: why your data is at risk

Common passwords such as “123456” are among the first combinations attackers try. A predictable password can put confidential information about the people you serve at risk.

Community organizations in Quebec handle sensitive information every day: membership records, financial information, health information and personal contact details. Yet cybersecurity often competes with limited IT budgets. Passwords are an important place to start.

Common passwords attackers try first

  • 123456 and variants such as 12345, 123456789 and 1234567890
  • password and motdepasse
  • qwerty and azerty
  • Your organization's name followed by 2026
  • admin or admin123
  • bienvenue and welcome
  • Common first names followed by numbers, such as sophie123 or martin2025
  • iloveyou

If any of these look familiar, it is time to review your password practices.

Why this matters for your organization

A weak password can give an attacker access to much more than one account.

Ransomware

An attacker who gains access to your network may encrypt files and demand payment to restore them. Community organizations with limited security resources can be particularly vulnerable to disruption.

Theft of personal information

The records of the people you serve can contain highly sensitive information. A breach may expose them to identity theft or fraud and damage their trust in your organization.

Privacy responsibilities

Quebec's Law 25 places responsibilities on organizations that handle personal information. Account security is part of protecting that information. Your privacy officer and advisers can help assess the obligations that apply to your organization.

Reputational damage

Trust is one of your most valuable assets. A security incident can affect relationships with partners, funders and the people you support.

Five practices for stronger passwords

1. Use long, unpredictable passwords

Longer passwords and passphrases are generally harder to guess. Aim for at least 16 characters where supported, avoid predictable phrases and never reuse an example printed in an article as your own password.

2. Use a password manager

A password manager stores unique credentials in an encrypted vault and can generate random passwords. Choose a solution suited to your organization's access and account recovery needs, and protect the vault with a strong master password and multifactor authentication.

3. Enable multifactor authentication (MFA)

MFA adds another verification step, such as an authenticator app or a security key. It significantly reduces the risk of a stolen password being enough to access an account. Review the available options for Microsoft 365 and other critical applications.

4. Never reuse a password

When credentials are exposed in a breach, attackers may try them on other services. A unique password for each account helps prevent one compromised service from affecting the rest.

5. Train employees and volunteers regularly

Technology alone is not enough. Short, regular sessions can help your team recognize phishing, use password managers and report suspicious activity. Make it easy for people to ask for help.

How Solutions MC can help

Solutions MC supports community organizations across Quebec with practical cybersecurity services:

  • Security assessments of existing systems and practices
  • MFA deployment and configuration for Microsoft 365 and critical applications
  • Password manager setup tailored to your team
  • Cybersecurity training for employees and volunteers
  • Proactive infrastructure monitoring to identify threats
  • Technical support for Law 25 compliance and personal information protection

We understand the realities of community organizations: limited budgets, small teams and volunteers to train. Our approach is practical and adapted to your size.

Take the next step

Weak passwords put your data and your community's trust at risk. Start by reviewing critical accounts, replacing reused passwords and enabling MFA.


Want to know how well your systems are protected? Our IT experts offer a free, no-obligation assessment of your cybersecurity posture. Request your free IT assessment.

Unsure about your compliance?

Get peace of mind. Assess the resilience of your systems in just 15 minutes with our expert assessment.

Get a free assessment

No obligation. Confidential.