10/03/2026 | Press release | Distributed by Public on 10/03/2026 00:24
The defensive strategy of "Hinten zu null und vorne hilft der liebe Gott" may have worked in the football of the past century. But you cannot build a fortress of computer security with terms from Germany's favorite ball sport. You never really could. Still, football club names are much more popular for protecting sensitive data than, for example, band names or classic films.
Anyone who scours every corner of the global web for stolen passwords and ranks them by frequency will find "schalke04" ahead of "liverpool1." Deutsche Telekom has compiled an all-time table of such findings. National team coach Jürgen Klopp normally likes to see his former clubs at the top. In an all-time table of stolen passwords, that is not the case. After classics such as "abc123," fans of the Bundesliga club promoted from Gelsenkirchen dominate the football picture from a club perspective, both worldwide and in Germany. Not only in lowercase does "schalke04" come out on top - more than 600,000 times globally - it also appears in uppercase more than 200,000 times in Germany alone.
The most persistent challenger at home comes from the second division. There is no getting around "hannover96"-in either spelling. Fans of "dortmund09" have to acknowledge that without envy: in Germany, their passwords have been exposed to third parties around 30,000 fewer times.
In Germany, the figures look like this:
| 01. schalke04 | 539,093 findings |
| 02. Schalke04 | 202,887 |
| 03. hannover96 | 89,654 |
| 04. Hannover96 | 56,177 |
| 05. dortmund09 | 54,181 |
| 06. hamburg1 | 52,600 |
| 07. Dortmund09 | 38,440 |
| 08. borussia09 | 37,618 |
| 09. Hamburg1 | 35,254 |
| 10. Borussia09 | 31,625 |
| 11. werder123 | 28,495 |
| 12. Schalke04! | 28,011 |
| 13. fcschalke04 | 25,688 |
| 14. fortuna95 | 22,567 |
| 15. dortmund1 | 22,481 |
| 16. fcbayern1 | 21,257 |
And overall? The frequency with which it appears shows why P@ssw@rd is not a strong password. Any predictable variation of this word-whether using numbers or special characters-should be off limits. They are extremely insecure.
But it is not just these, says Telekom Security Chief Thomas Tschersich: "The password itself is becoming obsolete. Yet it still protects sensitive information today. If additional security factors are available, you should use them. If you can replace the password entirely with a passkey, that is even better."
About Deutsche Telekom: Deutsche Telekom Group profile