Geslar logo
Geslar
2 min read

50 most common Croatian passwords

Passwords from publicly available breach databases. If yours is on the list — change it immediately.

Where does this data come from?
Every year, security researchers analyze billions of compromised passwords from publicly available breach databases. This list is based on an analysis of passwords from Croatian domains (.hr) and services popular in Croatia, published in databases such as HaveIBeenPwned.

These aren't fictional passwords — these are real passwords from real Croatian users that leaked in hacking attacks. Each of them is in the dictionaries that attackers use for credential stuffing attacks.

Important: If you recognize your password on this list, change it IMMEDIATELY on all services where you use it. Use a password manager to generate unique, strong passwords.

Top 25 — the worst of the worst
#PasswordTime to crack
1123456< 1 second
2lozinka< 1 second
3123456789< 1 second
4croatia< 1 second
5dinamo< 1 second
6hajduk< 1 second
7password< 1 second
8hrvatska< 1 second
9qwerty< 1 second
1012345678< 1 second
11zagreb< 1 second
12iloveyou< 1 second
13marko123< 1 second
14111111< 1 second
15dragon< 1 second
16ana123< 1 second
17split< 1 second
18ivan123< 1 second
19abc123< 1 second
20master< 1 second
21dalmatina2 seconds
22maja20003 seconds
23ljubav< 1 second
24sunce< 1 second
25000000< 1 second
Positions 26-50
#PasswordTime to crack
26admin< 1 second
27welcome< 1 second
28rijeka< 1 second
29monkey< 1 second
30tomislav2 seconds
31letmein< 1 second
32adriatic2 seconds
331234< 1 second
34football< 1 second
35mate19905 seconds
36qwerty123< 1 second
37josip< 1 second
38nikola< 1 second
39marina< 1 second
40osijek< 1 second
41majka1232 seconds
42tesla< 1 second
43corvette2 seconds
44vatreni< 1 second
45plitvice3 seconds
46dubrovnik3 seconds
47soccer< 1 second
48modric< 1 second
49petar< 1 second
50sunshine< 1 second
Why do people choose passwords like these?
Personal information
Names (marko123, ana123, ivan123), cities (zagreb, split, rijeka), football clubs (dinamo, hajduk). Hackers try these first.
Keyboard walk
qwerty, 123456, abc123 — fingers just sliding across the keyboard. These are literally the first passwords that cracking tools try.
Emotions and pop culture
iloveyou, ljubav (love), sunce (sun), dragon, vatreni (blazers) — emotional words and pop culture references are in every attack dictionary.
Name + year
maja2000, mate1990 — a combination of name and birth year. Hackers use name dictionaries combined with every year from 1950 to 2010.
What to do if your password is on the list?
1. Change it immediately
On EVERY service where you use that password. Not just one — credential stuffing attacks try the same password everywhere.
2. Use a password manager
Geslar generates a unique, strong password for every service. You only remember one master password — Geslar remembers all the rest.
3. Enable 2FA
Two-factor authentication is your safety net. Even if someone learns your password, without the second factor they can't access the account.
4. Check breach databases
Use the Geslar security check to check your password and email. Find out which data breaches have affected you.

Replace your weak password with a strong one — right now, for free.

Generate a secure password with Geslar →

Author
Daniel Legin
Daniel Legin builds Geslar — a free password generator and manager made in Croatia.
More about Geslar →