NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Over 1400 Western Australian government officials used 'Password123' as their password

By Taylor Telford for Washington Post
NZ Herald·
22 Aug, 2018 06:46 PM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

A survey has shown that Government officials are as lazy as everyone else when it comes to selecting passwords. Photo/123RF.

A survey has shown that Government officials are as lazy as everyone else when it comes to selecting passwords. Photo/123RF.

Somewhere in Western Australia, a government IT employee is probably laughing or crying or pulling their hair out, or maybe all of the above. A security audit of the Western Australian government released this week by the state's auditor general found that 26 per cent of its officials had weak, common passwords -- including more than 5,000 including the word "password" out of 234,000 in 17 government agencies.

The legions of lazy passwords were exactly what you - or a thrilled hacker - would expect: 1,464 people went for "Password123" and 813 used "password1." Nearly 200 individuals simply used "password," perhaps never changing it to begin with. Almost 13,000 used variations of the date and season, and almost 7,000 included versions of "123."

The laxness might be amusing, but the potential consequences definitely aren't. Many of these accounts are used to access important information and vital government systems, according to the report -- and several can do so remotely, with no additional vetting or credentials. Auditors were able to access one agency's network, with full system-administrator privileges, by guessing the password: "Summer123." Overall, the report found that most agencies didn't help users store their information safely and securely; this meant some employees were storing their passwords in Word documents or spreadsheets.

"After repeatedly raising password risks with agencies, it is unacceptable that people are still using password123 and abcd1234 to access critical agency systems and information," Auditor General Caroline Spencer said, according to reporting from Western Australia Today.

In the wake of the report, the government has agreed to step up its security game. It's developing practices to help employees store their password information more securely. The new Office of Digital government will house a cybersecurity team dedicated to improving security practices governmentwide.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Recent years have seen several huge data breaches at major companies. In 2013, an email account breach at Yahoo exposed the data of 3 billion users. In a 2016 breach at the FriendFinder Network - which included adult content and casual hookup sites like FriendFinder, Penthouse.com and Stripshow.com -- hackers accessed 20 years of data, including passwords and personal information. In 2017, a breach at major U.S. credit bureau Equifax exposed the personal information, including Social Security Numbers, birth dates, addresses and drivers' license numbers, of 143 million consumers.

Weak passwords are easy target for hackers. Last year, Verizon's annual Data Breach Investigations Report, which looked at hacking incidents at 65 companies, found that "81 percent of hacking-related breaches leveraged stolen and/or weak passwords." This number has gone up from 50 percent in the past three years.

This isn't a problem specific to the Western Australian government. In 2014, a U.S. Senate cybersecurity report found that several major breaches in important government agencies, including the Department of Homeland Security, the Internal Revenue Service and the Nuclear Regulatory Commission.

Advertisement
Advertise with NZME.

"Data on the nation's weakest dams, including those which could kill Americans if they failed, were stolen by a malicious intruder," the report said. "Nuclear plants' confidential cybersecurity plans have been left unprotected. Blueprints for the technology undergirding the New York Stock Exchange were exposed to hackers."

An analysis of these agencies' cybersecurity practices found tendencies mirroring the Western Australian practices: use of "password" was common for sensitive accounts and databases, as was poorly stored and guarded credential information.

Even unskilled hackers can use resources like lists of common passwords or publicly available personal information to break into accounts. The Romanian hacker Marcel Lehel Lazar, known online as "Guccifer," who first revealed Hillary Clinton was using a private email address as secretary of state, was far from a hacking expert. He told the New York Times he broke into more than 100 accounts, including several high-profile figures like Clinton's adviser Sidney Blumenthal and former Secretary of State Colin Powell, merely by guessing based on their personal information from their Wikipedia pages. (A fun fact: Guccifer was also responsible for leaking former President George W. Bush's paintings.)

The traditional guidelines for strong passwords -- making them long and complicated, including symbols and a mix of upper and lowercase letters, changing them regularly -- were actually making it easier for hackers, Paul Grassi of the National Institute of Standards and Technology told NPR last June. The organization's current guidelines for good passwords dovetails sharply with past wisdom: Passwords should be simple, long and easy to remember. It suggests using normal English words and phrases that are easy for users, but tougher on hackers.

Discover more

Business

It's BlackBerry, but not as you know it

21 Aug 05:00 PM
World

Bombshell: Trump 'implicated in crime'

21 Aug 11:28 PM
Business

Facebook says Russia, Iran created 652 phony pages

22 Aug 12:14 AM
World

Hackers target Democrats' voter data

22 Aug 06:38 PM

To keep accounts secure, pick something that's lengthy and memorable; if you change it, switch more than a single letter or digit. And for heaven's sake, don't use the word "password."

- Washington Post

Save

    Share this article

Latest from Business

Premium
Media Insider

6pm TV news battle: Are 1m people really still watching? The numbers are in

25 Jun 05:02 PM
Media Insider

'Hostile from outset': Heather du Plessis-Allan on Ardern, Luxon and evasive politicians

25 Jun 05:02 PM
New Zealand

New AI service to revolutionise how Kiwis compare energy plans

25 Jun 05:00 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
6pm TV news battle: Are 1m people really still watching? The numbers are in

6pm TV news battle: Are 1m people really still watching? The numbers are in

25 Jun 05:02 PM

TVNZ boss raised some eyebrows in political circles with ratings comments - is she right?

'Hostile from outset': Heather du Plessis-Allan on Ardern, Luxon and evasive politicians

'Hostile from outset': Heather du Plessis-Allan on Ardern, Luxon and evasive politicians

25 Jun 05:02 PM
New AI service to revolutionise how Kiwis compare energy plans

New AI service to revolutionise how Kiwis compare energy plans

25 Jun 05:00 PM
Premium
Moana Pasifika's future in doubt as key funding contracts end

Moana Pasifika's future in doubt as key funding contracts end

25 Jun 05:00 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP