PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

All PINs Leaked on the Interwebs!

By Mercator Advisory Group
September 26, 2012
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on LinkedIn

Personal identification numbers (PINs) remain one of the most widely used forms of payment authentication, protecting everything from debit cards to mobile devices. In theory, a four-digit PIN offers 10,000 possible combinations, but human behavior tells a different story. Consumers consistently favor memorable patterns, repeated digits, and sequential numbers, creating predictable choices that dramatically weaken security. An analysis of millions of PINs from publicly available data illustrates just how concentrated these selections have become and raises important questions about the effectiveness of PIN-based authentication as fraudsters become increasingly sophisticated.

Of course, the title of this feature is a hoax. There are only 10,000 possible combinations for four-digit PINs, and their “leaking” on the Internet has been a running joke for some time. The actual story is a bit different.

A very interesting analysis project on PINs was conducted by blog Datagenics that examined consumer use of PINs for their payment card accounts and other access codes. Using “data condensed from released/exposed/discovered password tables and security breaches” that yielded an impressive 3.4 million PINs, the researchers drew some exceedingly illustrative results and conclusions that should get the payments industry thinking about the relative viability of current authentication procedures.

Here’s one snippet:

The most popular password is 1234. [I]t’s staggering how popular this password appears to be. Utterly staggering at the lack of imagination…nearly 11% of the 3.4 million passwords are 1234!!!

The next most popular 4-digit PIN in use is 1111 with over 6% of passwords being this. In third place is 0000 with almost 2%.

A table of the top 20 found passwords in shown at the right. A staggering 26.83% of all passwords could be guessed by attempting these 20 combinations!

(Statistically, with 10,000 possible combination, if passwords were uniformly randomly distributed, we would expect the these twenty passwords to account for just 0.2% of the total, not the 26.83% encountered)

Looking more closely at the top few records, all the usual suspects are present 1111, 2222, 3333, 9999 as well as 1212 and (snicker) 6969.

The findings reinforce a simple but important lesson: authentication is only as strong as the choices consumers make. While PINs continue to serve as a valuable layer of security, easily guessed combinations significantly reduce their effectiveness and increase fraud risk. Financial institutions can help mitigate these vulnerabilities by discouraging common PIN selections, encouraging stronger authentication practices, and supplementing PINs with technologies such as biometrics, tokenization, and multi-factor authentication. As payment security continues to evolve, combining consumer education with stronger authentication methods will remain essential to protecting accounts.

Click here to read more from Data Genetics.

0
SHARES
0
VIEWS
Share on LinkedIn

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    AI fraud prevention for credit unions

    When AI Changes Fraud, Trust Becomes Everything

    August 17, 2026
    fednow

    How the Evolving Role of the CFO Is Changing Payments Strategy

    August 14, 2026
    real-time payment fraud prevention

    How Innovation Is Transforming Payment Fraud Prevention

    August 13, 2026
    phygital payments

    Why People Still Want Physical Things in a Digital World

    August 12, 2026
    AI debt collection, Apple Pay transaction growth

    How AI Makes Collections More Human—and More Effective

    August 11, 2026
    FedNow Service

    The Use Cases Propelling the FedNow® Service’s Growth—and Shaping Its Future

    August 10, 2026
    merchant debit fee

    Culture Clash: How Banks Are Adapting to Embedded AI Experts

    August 7, 2026
    programmatic payments

    The Rise of Programmatic Payments and the New Compliance Challenge

    August 6, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result