We came across an interesting, somewhat paradoxical story about this a while ago (unfortunately, we can’t find the original article anymore…).
The idea is that when users are forced to change their passwords frequently, it becomes a hassle, and they start rotating and reusing the same few passwords.
Eventually, as security requirements tighten and previously used passwords are disallowed, people often resort to changing just the last digit, moving up by one each time. Other shortcuts include reusing passwords across different systems or creating simple patterns they can tweak with each required change.
This approach is clearly counterproductive and can actually increase security risks.
It’s still essential to change passwords regularly. Thankfully, there are now plenty of tools to help manage passwords securely, so it’s a good idea to use these resources and ensure your passwords are well-protected.