How it works
A brute-force attack repeatedly tests possible secrets until one works. Against an online login, each guess reaches the service and can be rate-limited. Against stolen password hashes or an encrypted file, guessing may happen offline, outside the login service’s controls.
A practical example
Repeated failed sign-ins might target an email account with a short password. A different attacker may test many candidate passwords against a stolen database. In both cases, password length matters, but the protection available to the account owner differs.
What to check
Use a long, unique password or a supported passkey, enable additional authentication and protect recovery methods. Review unexpected successful logins, not only failed attempts. For an organisation, rate limits and monitoring should be configured without allowing attackers to lock everyone out.
For a legitimate user locked out after repeated attempts, use the provider’s verified recovery route. Repeatedly retrying the same rejected password can delay access without resolving the underlying cause.
Limits and safe use
Credential stuffing tries previously leaked username-password pairs, rather than systematically exploring every possibility. A change to one reused password does not protect other accounts still using it. Offline resistance also depends on how a service stores passwords; a user cannot verify that from password length alone.