Security

Brute-Force Attack

Repeated automated guesses against a password or other secret. Long unique passwords, rate limits and additional sign-in factors make this harder; some attacks instead try passwords leaked from other services.

How it works

A brute-force attack repeatedly tests possible secrets until one works. Against an online login, each guess reaches the service and can be rate-limited. Against stolen password hashes or an encrypted file, guessing may happen offline, outside the login service’s controls.

A practical example

Repeated failed sign-ins might target an email account with a short password. A different attacker may test many candidate passwords against a stolen database. In both cases, password length matters, but the protection available to the account owner differs.

What to check

Use a long, unique password or a supported passkey, enable additional authentication and protect recovery methods. Review unexpected successful logins, not only failed attempts. For an organisation, rate limits and monitoring should be configured without allowing attackers to lock everyone out.

For a legitimate user locked out after repeated attempts, use the provider’s verified recovery route. Repeatedly retrying the same rejected password can delay access without resolving the underlying cause.

Limits and safe use

Credential stuffing tries previously leaked username-password pairs, rather than systematically exploring every possibility. A change to one reused password does not protect other accounts still using it. Offline resistance also depends on how a service stores passwords; a user cannot verify that from password length alone.

Technical sources

← All glossary terms