News

Messi Beats Ronaldo in Unexpected Scenario: Password Breach Data Report Reveals How Often Football Names Occur in Stolen Credentials Ahead of FIFA World Cup 2026

One place where Lionel Messi outpaces Cristiano Ronaldo by 26% is real-world breached password dataset base analyzed for a recent cybersecurity report.

Messi Beats Ronaldo in Unexpected Scenario: Password Breach Data Report Reveals How Often Football Names Occur in Stolen Credentials Ahead of FIFA World Cup 2026

Specops, a password security company owned by Outpost24, analyzed more than 6.4 billion compromised passwords and found football player and club names appearing frequently in breached credential datasets, just weeks ahead of the 2026 FIFA World Cup that takes place in the US, Canada and Mexico from 11 June to 19 July 2026.

In the dataset, the name “Messi” appeared 1,221,563 times and “Ronaldo” appeared 923,582 times. Except these two leading football players used for password creation, the top ten player names by occurrence included: Vinicius (1,198,898), Salah (1,123,062), Saka (1,019,325), Kane (987,335), Fernandes (804,159), Gavi (683,831), Isak (682,702), and Pedri (394,639).

Club names also appeared in the data. “Roma” recorded the highest occurrence count at 5,340,687, significantly ahead of others in the top ten. The researchers noted this figure likely reflects the word’s use beyond the football club. Other football clubs people used for their real-world passwords that were ultimately compromised were Porto, Barcelona, Leon, Napoli, Chelsea, Everton, PSG, etc.

The researchers noted that though football names and clubs are not sensitive personal data easily linked to the individual, they are not the strongest choice for the protection of one’s accounts. In the researchers’ experience, password-cracking tools such as Hashcat and John the Ripper use wordlists with rule-based mutations, appending years, substituting letters for numbers, adding symbols, and leveraging other similar technics, meaning that once a term appears in a wordlist, many of its variants are tested automatically and breached over time.

Each year, an estimated number of 24 billion credentials are exposed globally through data breaches. Whether by malware or phishing scams, thousands of people lose control over their social media, messenger and bank accounts each day. Considering the frequency of repeat password use for multiple platforms, the ripple effects of a single data point breach quickly affect numerous user’s login credentials. A recent study by Cybernews analyzed over 19 billion passwords exposed in data breaches between April 2024 and April 2025 and found that 94% of passwords were reused or duplicated across multiple accounts. Different industry analyses show smaller shares of 70%-80%, but the overall tendency is clear.

To avoid getting your password compromized, NIST latest guidance advises to choose longer, memorable passwords or passphrases over rigid character requirements, adding multi-factor authentication (MFA) methods including biometric protection, and use publicly available free tools to check whether their email address has appeared in a known data breach.

Nina Bobro

Nina Bobro

2064 Posts

https://payspacemagazine.com/author/nb/

Nina is passionate about financial technologies and environmental issues, reporting on the industry news and the most exciting projects that build their offerings around the intersection of fintech and sustainability.