This situation is so bad in India, that I can't even begin to summarise it... The biggest culprits are financial institutions themselves - they have such stupid requirements for passwords - need to change it regularly, can only contain @#!, need one caps, one small, one number, can't be the same as last 5 times, can't be shorter than 8 chars, but can't be longer than 15 chars either(!?!), etc - that you are either forced to write it down somewhere, or need to necessarily use a password manager. For the less computer savvy people, the second option is a non-starter, so they resort to the first option. And then, these stupid banks and mutual fund companies actively try to sabotage the working of password managers, and even disabling paste on password fields.
And then, there are incredible incidences like this: I received an SMS from a loyalty program a few weeks back:
Login at www.raymondrewards.com with your mobile no. & password <base-64 encoded string> for program benefits. Update your birthday & get 750 bonus pts in your birthday month.
And I just sank in utter despair.