A brute force attack is an attempt to guess a password, encryption key or other secret by systematically trying many or all possible combinations until one works.
How brute force attacks work
The simplest form tries every possible combination. Practical attacks are smarter:
- Dictionary attacks try common passwords, leaked lists and their variations (“Summer2025!”).
- Password spraying tries a few popular passwords against many accounts to avoid lockouts.
- Credential stuffing reuses username–password pairs from earlier breaches.
- Offline cracking works on a stolen database of password hashes; tools such as hashcat test billions of guesses per second on GPUs.
Online attacks target any login exposed to the internet: RDP, SSH, VPN gateways, mail and web admin panels. Botnets distribute attempts across thousands of IP addresses to stay below rate limits.
Why password length matters
The work grows exponentially with length and character set. Eight lowercase letters give about 2×1011 combinations, which a GPU rig can check in seconds if the hash is fast; a random 16-character passphrase is out of reach. Strong encryption keys such as AES-256 cannot realistically be brute-forced at all, which is why attackers target passwords and people instead.
How to defend
- Enable multi-factor authentication, ideally two-factor authentication with passkeys or hardware keys.
- Limit login attempts, add delays and monitor failed logins; never expose RDP directly to the internet.
- Encourage long passphrases and block known breached passwords.
- Store passwords with slow, salted algorithms such as Argon2 or bcrypt.