
Australians are not short on password advice. The trouble is that a good deal of it is out of date, and some of it has been formally withdrawn by the organisations that wrote it in the first place. Meanwhile, the risk has not gone anywhere: the Office of the Australian Information Commissioner received 1,205 data breach notifications in 2025, the highest number since mandatory reporting began in 2018 and an 8% increase on the year before. Here are seven password myths worth retiring, and what the current guidance actually says.
Myth 1: A strong password needs a capital, a number and a symbol
This is the rule almost every website taught us, and it is the one experts have turned against most sharply. In its updated Digital Identity Guidelines, the US National Institute of Standards and Technology scrapped mandatory composition rules altogether. The reason is that these rules produce painfully predictable results. Told to add a capital, a number and a symbol, most people produce something like P@ssw0rd1! — and password-cracking tools have known every one of those letter-for-symbol substitutions for years. Length, not decoration, is what makes a password hard to crack.
| What to do instead: Use a passphrase. Australia’s own cyber security agency recommends four or more random, unrelated words — something in the order of 15 characters or more. It is longer, stronger and far easier to recall than a mangled single word. |
Myth 2: You should change your passwords every few months
This one has not merely fallen out of fashion; it has been reversed. Current guidance is that passwords should be changed when there is evidence of compromise — not because the calendar says so. Forced rotation was found to make things worse rather than better, because people under pressure to invent a new password every 90 days do the obvious thing: Summer2025! becomes Summer2026!, and attackers know the pattern. Australia’s guidance now points the same way, recommending rotation only where compromise is suspected.
| What to do instead: Change a password when you have a reason: a breach at a company you use, a password you once shared with someone, or anything that looks odd on the account. Otherwise, leave a strong, unique password where it is. |
Myth 3: Adding a number on the end makes it a different password
Netflix1 and Netflix2 are not two passwords. They are one password with a rounding error. When criminals get hold of a list of leaked logins, they do not sit there typing them in — they run automated tools that try each combination across hundreds of other sites, and those tools test the obvious variations as a matter of course. A small tweak buys you nothing. There are plenty of other mistakes hackers are hoping you will make, but this is among the most common.
| What to do instead: Make each password genuinely unrelated to the others — not a variation on a theme. |
Myth 4: Your password is only at risk if you do something careless
This is the comforting one, and it is wrong. Most leaked passwords are not handed over by their owners; they are taken from companies that were holding them. Of the 1,205 breaches notified to the OAIC in 2025, 716 were down to malicious or criminal activity, and health service providers were the single most affected sector, accounting for 19% of all notifications. You can do everything right and still find your password circulating, because the weak link was a database you never saw.
| What to do instead: Assume that any given password will eventually leak, and make sure that when it does, it opens exactly one door rather than forty. |
Myth 5: You would hear about it if your details leaked
Not necessarily, and not quickly. Research by KnowBe4 and YouGov found that 24% of Australians take no action at all after hearing about a major data breach unless they are personally notified. That is a quarter of the country waiting for a letter while their credentials are already being tested elsewhere. Breaches also take time to discover, and longer still to report.
| What to do instead: Do not wait to be told. If a company you use is in the news, change that password now — and while you are at it, change it anywhere else you have used it. |
Myth 6: Writing your passwords down is the worst thing you can do
This is the myth that does the most quiet damage, because it is only half true. A sticky note on the monitor at work is a genuinely bad idea. A notebook in a drawer at home is a different proposition entirely — the criminals running automated attacks against your accounts are not in your kitchen. Compared with using one password across every account you own, a notebook is the lesser risk by some distance. The problem with paper is not really security. It is that it does not scale, it cannot help you at the checkout, and it will not tell you when something has leaked.
| What to do instead: Use a password manager. It is the notebook idea done properly: it stores every login behind one strong passphrase, generates long random passwords so you never have to invent them, and fills them in for you. You remember one thing. It remembers the rest. |
Myth 7: You ought to be able to remember them all
Roughly two-thirds of Australians reuse passwords across multiple accounts, and the reason is not laziness. One survey of 1,000 Australians found that 47% put their password reuse down to the difficulty of remembering multiple unique logins, with another 33% citing time. That is not a character flaw. The average person now has dozens of accounts, and remembering dozens of long, random, unrelated strings is not something human memory was built to do. Treating it as a personal failing is precisely why the problem persists.
| What to do instead: Stop trying. Remember one strong passphrase, let software carry the rest, and turn on two-factor authentication wherever it is offered — so that even a leaked password is not enough on its own. |
The short version
Longer beats fancier. Unique beats memorable. Change a password when something happens, not when the calendar tells you to. And if you cannot remember them all, that is not a failing to be fixed with willpower — it is a job to hand to something that does not forget.
Broght to you by



