ADAM PULSE Knowledge Base
Cybersecurity · Authentication · Password Attacks

What is a brute force attack, and how do you stop one?

The short answer: A brute force attack is an attempt to gain unauthorized access to an account, device, application, or network service by repeatedly trying usernames and passwords until something works. Because attackers can automate these attempts, a business can face hundreds or thousands of login attempts without a person manually typing every password.

The best defense is not one single control.

Businesses should combine:

Strong unique credentials

Multifactor authentication

Limits on repeated login attempts

Secure remote access

Reduced internet exposure

Monitoring and alerting

Removal of unused accounts

Appropriate firewall controls

and

Investigation of suspicious authentication activity.

A brute force attack sounds unsophisticated.

In many ways, it is.

But something does not have to be sophisticated to be effective.

If attackers can try enough doors, enough usernames, and enough passwords automatically, eventually they may find an organization that has left one open.

What Is a Brute Force Attack?

A brute force attack repeatedly attempts authentication credentials in an effort to gain access.

Think about a locked door with a keypad.

A person could stand in front of it and try:

0000

0001

0002

0003

and continue until something works.

That would take a long time.

Software changes the equation.

Computers can perform repetitive tasks continuously.

An attacker can automate credential attempts against:

The attacker does not necessarily need to know the correct password.

They need an opportunity to keep trying.

Why Are Brute Force Attacks Still a Problem?

Because passwords still protect enormous amounts of technology.

Businesses use credentials for:

Every login presents an authentication challenge:

Are you really who you claim to be?

If the only evidence required is a password, an attacker can attempt to discover that password.

This is one reason modern cybersecurity increasingly emphasizes multifactor authentication rather than relying solely on passwords.

Does a Hacker Have to Manually Type Every Password?

No.

This is the most important concept for nontechnical readers.

A brute force attack can be automated.

Instead of imagining a hacker sitting at a keyboard entering:

password1

password2

password3

imagine software doing the work.

The software can run:

During lunch.

At night.

On weekends.

During holidays.

While the attacker sleeps.

Automation fundamentally changes the economics of the attack.

Trying one password manually may not be worthwhile.

Trying thousands of possible credentials automatically can be.

How Does a Brute Force Attack Work?

A simplified attack can follow this pattern:

Step 1: Find a Login

The attacker discovers a system that accepts remote authentication.

Examples might include:

Step 2: Identify or Guess a Username

The attacker may try common usernames or known employee accounts.

Step 3: Try Passwords

Automated software begins attempting likely passwords.

Step 4: Observe the Result

The application responds:

Rejected

or:

Accepted

Step 5: Continue or Stop

If authentication fails, the system continues trying.

If authentication succeeds, the attacker may begin exploring what the account can access.

The password attack is not necessarily the final objective.

It may simply be the front door.

What Passwords Do Attackers Try First?

Attackers do not necessarily begin by testing completely random strings.

They can start with passwords humans are likely to use.

Common categories include:

People are predictable.

Attackers know that.

An employee may think:

Summer2026!

is clever because it contains:

But attackers understand common human password patterns.

Complexity alone does not guarantee unpredictability.

Is “Password123!” Really That Dangerous?

Potentially, yes.

Adding predictable numbers and punctuation to a common word does not necessarily create a strong password.

Attack tools can be designed to test common variations.

For example:

Password

Password1

Password123

Password123!

may all be included in password guessing strategies.

This is why modern password guidance increasingly emphasizes:

Length

Uniqueness

Avoiding known compromised passwords

and

Using password managers

rather than simply requiring one uppercase letter and one symbol.

What Is a Dictionary Attack?

A dictionary attack is a form of password guessing that uses a prepared list of likely passwords.

Instead of attempting every possible combination, the attacker prioritizes:

This can make password guessing more efficient.

The attacker is effectively saying:

“Before I try everything, let me try what people usually choose.”

What Is Password Spraying?

Password spraying reverses the traditional brute force approach.

Instead of:

One account

↓

Thousands of password attempts

the attacker may use:

One common password

↓

Many accounts

For example, instead of trying 10,000 passwords against one employee, an attacker might test one likely password against hundreds of employee accounts.

Why?

Because repeated failures against one account may trigger a lockout.

Spreading attempts across many accounts may make the activity less obvious.

This is called password spraying.

Why Is Password Spraying Dangerous for Businesses?

Businesses frequently create predictable account structures.

For example:

firstname.lastname@company.com

Employee names may be publicly visible through:

An attacker may therefore have a list of valid or probable usernames before the attack begins.

They can then test common passwords across those accounts.

This makes password security an organizational issue, not simply an individual employee responsibility.

What Is Credential Stuffing?

Credential stuffing is different from traditional brute force.

Instead of guessing a password, attackers use passwords that were already stolen elsewhere.

Imagine an employee uses:

MyGreatPassword123!

for a personal website.

They use the same password for their company account.

The personal website suffers a breach.

Attackers obtain:

Employee email address

plus

MyGreatPassword123!

They automatically test that combination against:

If the employee reused the password, the attack may succeed.

This is why every important account should use a unique password.

Brute Force vs. Password Spraying vs. Credential Stuffing

These terms are related but different.

Brute Force

Try many passwords until one works.

Dictionary Attack

Try a prepared list of likely passwords.

Password Spraying

Try a small number of passwords against many accounts.

Credential Stuffing

Try already compromised username and password combinations against other services.

All four attacks exploit the same fundamental weakness:

Authentication depends too heavily on credentials that attackers can guess, obtain, or reuse.

How Do Attackers Know My Employees' Usernames?

Sometimes it is surprisingly easy.

Employee information may appear publicly through:

Businesses also frequently use predictable email naming conventions.

If an attacker discovers:

john.smith@company.com

they may reasonably assume:

jane.doe@company.com

follows the same format.

Cybersecurity does not mean hiding employee names.

It means designing authentication with the assumption that usernames may not be secret.

Can a Brute Force Attack Target My Firewall?

Potentially, yes.

If a firewall management interface or remote access service is reachable, attackers may attempt authentication.

This is why firewall administration deserves strong protection.

Businesses should ask:

Is the management interface accessible from the public internet?

Does it need to be?

Who is allowed to reach it?

Is MFA enabled?

Are failed authentication attempts logged?

Would someone notice repeated failures?

Is the firewall software current?

A firewall protects your network.

The firewall itself also needs protection.

Can a Brute Force Attack Target My VPN?

Yes.

VPN gateways are particularly important because successful authentication may provide access into internal business resources.

That makes VPN credentials valuable.

Remote access should therefore be protected using:

The FTC specifically recommends MFA for sensitive remote network access and strong security standards for employees and vendors connecting remotely.

Can Hackers Brute Force Remote Desktop?

Remote Desktop Protocol, commonly called RDP, can be targeted by automated authentication attempts when it is exposed.

Direct exposure of remote administrative services deserves careful security consideration.

Businesses should not simply expose remote access because:

“We need to reach that computer from home.”

Instead ask:

What secure architecture should provide that access?

Remote access can potentially be protected through:

Convenience should not automatically determine security architecture.

Can SSH Be Brute Forced?

Yes.

SSH is widely used for securely administering servers and network devices.

It is extremely useful.

It can also attract automated authentication attempts when publicly reachable.

Strong SSH security may involve:

SSH itself is not insecure simply because attackers target it.

The question is how it is configured and protected.

What Happens After a Brute Force Attack Succeeds?

This is where the attack can become considerably more serious.

Once an attacker obtains valid access, they may attempt to determine:

What system did I reach?

What permissions does this account have?

What else can I access?

Can I create another account?

Can I elevate privileges?

Can I disable security tools?

Can I access files?

Can I reach other computers?

Can I establish persistent access?

The password was only the key.

The real objective may exist behind the door.

What Is Privilege Escalation?

Privilege escalation occurs when an attacker who already has some access attempts to gain more powerful permissions.

For example:

Basic user

↓

Local administrator

↓

Domain or cloud administrator

An attacker may initially compromise an ordinary employee account.

But an ordinary account may provide a path toward more valuable systems.

This is why the principle of least privilege matters.

If every user has administrator permissions, compromise of one account can have greater consequences.

What Is Account Lockout?

Account lockout limits what happens after repeated failed authentication attempts.

For example:

After five unsuccessful logins, the system might:

The FTC specifically recommends limiting unsuccessful login attempts as protection against password guessing attacks.

This creates friction for automated attackers.

Does Account Lockout Completely Stop Brute Force Attacks?

No.

Account lockout can help, but it requires thoughtful configuration.

Why?

Because overly aggressive lockouts can create another problem.

Imagine an attacker knows your CEO's username.

They intentionally enter the wrong password repeatedly.

The CEO's account becomes locked.

The attacker has now created a denial of service condition.

This means businesses need to balance:

Security

with

Availability.

Different platforms offer different protections, including:

There is rarely one universal setting appropriate for every system.

What Is Rate Limiting?

Rate limiting restricts how frequently an action can occur.

For authentication, it may limit how quickly repeated login attempts can be made.

Instead of allowing:

1,000 attempts in one minute

the system may slow the process dramatically.

This reduces the efficiency of automated attacks.

Attackers benefit from speed.

Defenders can make speed expensive.

What Is Login Throttling?

Login throttling is similar.

The system intentionally slows authentication after repeated failures.

For example:

First failure:

Immediate retry

Later failures:

Wait several seconds

Then:

Wait longer

This makes automated password guessing progressively less efficient without necessarily creating a permanent lockout.

Different applications implement these protections differently.

Does CAPTCHA Stop Brute Force Attacks?

CAPTCHA can make some automated attacks more difficult by requiring evidence that a human is interacting with the login.

But CAPTCHA should not be the only protection.

Attackers have developed methods for working around many CAPTCHA systems.

The stronger strategy is layered:

Strong credential policy

plus

MFA

plus

rate limiting

plus

monitoring

plus

appropriate exposure controls.

Does a Strong Password Stop Brute Force Attacks?

A strong password can make guessing dramatically harder.

But password strength should not be the only control.

Even an excellent password can be:

This is why authentication should increasingly be designed around:

Strong password

plus

MFA

rather than:

Strong password and hope.

Why Does Password Length Matter?

Long passwords increase the number of possible combinations an attacker would need to consider.

Current password guidance places substantial emphasis on length.

Long passphrases can also be easier for people to remember than short, complicated strings.

For example, forcing someone to remember:

G7!xpQ#2

may encourage them to write it down or reuse it.

A longer memorable passphrase can provide stronger practical security when used appropriately.

Password managers make long random credentials even more practical.

Why Should Passwords Be Unique?

Because a unique password limits the impact of another service being compromised.

Imagine three accounts.

Scenario A

Email password:

SamePassword

VPN password:

SamePassword

Accounting password:

SamePassword

One credential leaks.

Three systems may be exposed.

Scenario B

Email:

Unique credential

VPN:

Different unique credential

Accounting:

Different unique credential

One service is compromised.

The other passwords remain unrelated.

Uniqueness creates containment.

Why Is MFA So Important Against Brute Force Attacks?

Because successful password discovery does not necessarily equal successful authentication.

Without MFA:

Password guessed

↓

Access granted

With MFA:

Password guessed

↓

Additional authentication required

↓

Attack may fail

This changes the value of the password.

The attacker now needs more than one factor.

The FTC recommends MFA for access to sensitive business information and remote network access.

Does MFA Stop Every Attack?

No.

Nothing does.

Attackers may attempt:

Some MFA methods are more resistant to these attacks than others.

This is why organizations protecting sensitive accounts should increasingly evaluate phishing resistant MFA.

But even imperfect MFA can provide significantly better protection than passwords alone.

What Is an MFA Fatigue Attack?

An MFA fatigue attack attempts to overwhelm or confuse a user with authentication requests.

The attacker may already know the password.

They repeatedly trigger:

Approve this login?

Approve this login?

Approve this login?

Eventually the employee may press:

Approve

just to make the notifications stop.

Employees should be trained:

> Never approve an authentication request you did not initiate.

An unexpected MFA prompt may be evidence that someone already knows the password.

Can Firewalls Stop Brute Force Attacks?

Firewalls can contribute to defense.

Depending on architecture and capabilities, they may:

But the firewall is only one layer.

If the service is intentionally exposed, the firewall may properly allow the connection to reach the login screen.

Authentication security then becomes critical.

Why Reducing Exposure Matters

Suppose your firewall's administrative interface should only be accessible internally.

Option one:

Expose it to the entire internet and rely on a strong password.

Option two:

Do not expose it publicly at all.

Option two significantly reduces who can even attempt authentication.

This is an extremely important security principle:

> The strongest login page against an attacker may be one the attacker cannot reach.

Secure authentication matters.

Reduced exposure matters too.

How Can I Tell if Someone Is Brute Forcing My Account?

Repeated failed authentication attempts are one of the most obvious indicators.

Monitoring may reveal:

Patterns are more informative than isolated events.

One failed login could be a typo.

One thousand failures deserve a different level of curiosity.

Is One Failed Login a Cyberattack?

Probably not enough information exists to say.

Users make mistakes.

Passwords change.

Applications store old credentials.

Mobile devices keep outdated passwords.

Services misbehave.

Security monitoring should not generate panic over every failed authentication.

The objective is to understand patterns.

Ask:

How many failures?

Against which account?

From where?

Over what period?

Did other accounts experience the same activity?

Did any attempt succeed?

What happened afterward?

Context turns data into information.

Why Is a Successful Login After Many Failures Important?

Consider:

300 failed attempts

followed by:

SUCCESS

That deserves investigation.

The critical questions become:

Was it the legitimate user?

Was the source expected?

Was MFA completed?

What device was used?

What did the account do next?

Were settings changed?

Were new accounts created?

Did data move?

A successful login can be more important than the hundreds of failures before it.

What Is Distributed Brute Force?

Attackers do not always send every login attempt from one computer.

They can distribute attempts across many systems.

This may involve:

Now the pattern becomes harder to recognize.

Instead of:

One IP address → 10,000 attempts

you might see:

1,000 IP addresses → 10 attempts each

Simple source blocking becomes less effective.

This is why businesses should focus on the behavior as well as the address.

Why Blocking One IP Address Is Not Enough

Blocking clearly malicious infrastructure can be useful.

But if the attacker has thousands of potential sources, manual blocking becomes an endless exercise.

The more important controls include:

MFA

account protections

rate limiting

proper exposure

strong credentials

behavioral monitoring

removal of unnecessary accounts

Blocking the attacker is useful.

Fixing the reason the attacker has an opportunity is more important.

What Is a Botnet?

A botnet is a collection of compromised systems that can be controlled or coordinated.

Those systems might include:

A criminal does not necessarily need to launch an attack from their own laptop.

They may use infrastructure belonging to other victims.

This makes attribution and simple IP blocking more complicated.

The computer attacking your network may itself be compromised.

Why Are Remote Access Systems Attractive Targets?

Because successful remote access can potentially put an attacker inside the business environment.

Examples include:

These systems deserve heightened protection.

Ask:

Does remote access need to exist?

Who needs it?

Is MFA enabled?

Can access be restricted?

Are unused accounts removed?

Are logs reviewed?

Is the software current?

Would repeated failures generate an alert?

Remote access should be treated as a controlled entry point.

What About Vendor Remote Access?

Vendors frequently need remote connectivity.

That can include:

Vendor access should not be automatically permanent or unrestricted.

Businesses should determine:

Who has access?

Why?

To what?

For how long?

Using which account?

Is MFA enabled?

Is activity logged?

What happens when the vendor relationship ends?

A forgotten vendor account can become another door.

Should Old Accounts Be Deleted?

Accounts that are no longer required should be disabled or removed according to appropriate business procedures.

Examples include:

Every unnecessary account creates another possible authentication target.

Attack surface is not limited to hardware.

Accounts are part of the attack surface too.

What Is an Authentication Attack Surface?

An authentication attack surface includes all the places where someone can attempt to prove an identity.

That may include:

Businesses should inventory these authentication points just as they inventory physical equipment.

Ask:

Where can someone log in?

That is a powerful cybersecurity question.

Are Administrative Accounts More Important to Monitor?

Yes.

Privileged accounts can often perform sensitive actions.

They may:

Repeated authentication attempts against an administrative account therefore deserve particular attention.

Administrative accounts should also receive stronger protections.

What Should a Business Do to Prevent Brute Force Attacks?

There is no one button labeled:

STOP BRUTE FORCE.

The strongest approach uses layers.

1. Enable MFA

Prioritize remote, cloud, privileged, financial, and administrative accounts.

2. Use Unique Passwords

Do not reuse credentials between services.

3. Use Long Passwords or Passphrases

Follow current platform and security guidance.

4. Use a Password Manager

Make unique credentials practical.

5. Limit Repeated Login Attempts

Use appropriate lockout, throttling, or rate limiting capabilities.

6. Reduce Public Exposure

Do not publish administrative login interfaces unnecessarily.

7. Secure Remote Access

Review VPN, SSH, RDP, remote support, and vendor access.

8. Patch Systems

Keep authentication and remote access infrastructure current.

9. Remove Unused Accounts

Do not leave old credentials available indefinitely.

10. Monitor Authentication

Look for suspicious failure and success patterns.

11. Protect Administrative Accounts

Use stronger controls for privileged access.

12. Train Employees

Teach employees to recognize suspicious MFA prompts and credential phishing.

What Should Happen When Repeated Failed Logins Are Detected?

A good process starts with curiosity.

Do not immediately assume:

“We have been hacked.”

But do not ignore the event either.

Investigate:

1. Which account is being targeted?

2. How many failures occurred?

3. Over what period?

4. Where are attempts originating?

5. Is one address involved or many?

6. Is the user legitimately having login trouble?

7. Did any authentication eventually succeed?

8. Was MFA triggered?

9. Is this account privileged?

10. What activity occurred after any successful login?

Those answers help determine urgency.

The Difference Between an Attempt and a Compromise

This distinction is extremely important.

An attempted login is not the same thing as a successful compromise.

Suppose your firewall records:

10,000 rejected login attempts.

That sounds frightening.

But the most important word may be:

Rejected.

Your controls may have worked.

Now compare that with:

20 failed attempts

followed by:

Successful administrator login

That smaller number may be much more significant.

Cybersecurity should focus on outcomes and context, not simply dramatic counts.

More Attacks Does Not Automatically Mean Less Security

This is another important lesson.

A company might report:

“Our firewall blocked 50,000 attacks this week!”

That number sounds impressive.

But what does it actually mean?

Were these:

Did anything succeed?

How were events classified?

Raw counts can be misleading.

Good security reporting should explain:

What happened

What was blocked

What succeeded

What requires attention

and

What should happen next.

Detection Without Context Creates Noise

Imagine receiving an email every time someone enters the wrong password.

Your employees might generate hundreds of alerts themselves.

Soon nobody pays attention.

That is alert fatigue.

Instead, monitoring should identify meaningful patterns.

For example:

One failed login

might not require action.

But:

500 failures against the firewall administrator

followed by:

a successful authentication from an unexpected source

should receive much more attention.

The objective is not more alerts.

The objective is better awareness.

Where USA Telecom and ADAM Fit

Brute force attacks illustrate an important monitoring principle.

The first event does not always tell the story.

One failed login may mean nothing.

A pattern may mean something.

A combination of events may mean much more.

That philosophy aligns closely with how USA Telecom and ADAM approach technology monitoring:

Detect conditions.

Look for context.

Validate what is happening.

Escalate meaningful events.

Investigate root cause.

ADAM is not intended to replace dedicated identity security, MFA platforms, SIEM systems, endpoint security, or firewall security.

Those systems have specialized functions.

The broader opportunity is to build better visibility and operational awareness across the technology environment.

Authentication Is Another Form of Network Visibility

Consider a multi location business.

It may have:

There are potentially thousands of authentication and connectivity events occurring.

The business should be able to answer:

Which systems are online?

Which services are exposed?

Who is authenticating?

Where are repeated failures occurring?

Did anything succeed unexpectedly?

Did availability change at the same time?

Visibility helps bring those questions together.

A Brute Force Attack Can Also Reveal a Configuration Problem

Suppose a company discovers that an administrative service receives thousands of login attempts every day.

That leads to an important question:

Why can the entire internet reach this login at all?

Maybe it must be exposed.

Maybe it does not.

The brute force activity might be the symptom.

The underlying issue may be unnecessary exposure.

This is why root cause analysis matters.

Do not only ask:

“How do we block the attacker?”

Ask:

“Why does the attacker have the opportunity to try?”

That is a much stronger security question.

20 Questions Every Business Should Ask About Remote Authentication

1. Which systems can be logged into from the internet?

2. Does each one need to be publicly reachable?

3. Is MFA enabled?

4. Are passwords unique?

5. Do employees use a password manager?

6. Are default credentials gone?

7. Are repeated login attempts limited?

8. Are failed login attempts logged?

9. Who receives authentication alerts?

10. Can we identify successful logins following repeated failures?

11. Are administrative accounts monitored more closely?

12. Is our VPN software current?

13. Is RDP directly exposed anywhere?

14. Is SSH exposed unnecessarily?

15. Can vendors remotely access our network?

16. Do vendor accounts use MFA?

17. Are former employee accounts disabled?

18. Are old vendor accounts removed?

19. Do employees know not to approve unexpected MFA requests?

20. Do we have a documented response process for suspicious authentication?

These questions move cybersecurity beyond:

“Do we have strong passwords?”

toward:

“Do we have secure authentication?”

The Better Question Is Not “How Strong Is Our Password?”

Password strength matters.

But the more complete questions are:

Can attackers reach the login?

How many attempts can they make?

Is the password unique?

Is MFA enabled?

Is the account privileged?

Are attempts monitored?

Would we recognize password spraying?

Would we recognize a successful login after repeated failures?

Can we quickly disable access?

Who investigates the alert?

That is the difference between a password policy and an authentication security strategy.

Key Takeaway

A brute force attack is simple in concept.

Try a password.

If it fails, try another.

Then another.

Then another.

Automation turns that simple idea into a scalable attack.

That is why businesses should not rely on a password alone to protect critical systems.

Protect accounts with layers:

Use long, unique passwords.

Use password managers.

Enable MFA.

Limit repeated attempts.

Reduce unnecessary exposure.

Protect remote access.

Patch authentication systems.

Remove unused accounts.

Monitor failed authentication.

Investigate unexpected successes.

And remember the larger principle:

> The goal is not merely to make passwords harder to guess. The goal is to make a guessed password insufficient to compromise the business.

Attackers can automate password attempts.

Businesses need to automate awareness of authentication activity.

And when an unusual pattern appears, someone needs to ask:

Why?

Frequently asked questions

What is a brute force attack?

A brute force attack repeatedly attempts passwords or credential combinations to gain unauthorized access to an account, application, device, or network service.

Are brute force attacks automated?

Frequently. Attackers can use software to perform large numbers of authentication attempts without manually typing each password.

How do hackers brute force passwords?

Attackers may use automated software to try common passwords, known password lists, predictable variations, or large numbers of possible combinations.

What is a dictionary attack?

A dictionary attack uses lists of likely passwords rather than attempting every possible character combination.

What is password spraying?

Password spraying tests a small number of common passwords against many accounts rather than repeatedly targeting one account.

What is credential stuffing?

Credential stuffing uses username and password combinations stolen from other sources and automatically tries them against additional services.

Why does password reuse make credential stuffing possible?

If the same password is used across multiple services, credentials exposed by one service may provide access to another.

Can MFA stop a brute force attack?

MFA can significantly reduce the likelihood that a guessed or stolen password alone results in successful authentication. It should be used particularly for sensitive, remote, and administrative access.

Can hackers brute force VPN passwords?

Internet accessible VPN services may receive automated authentication attempts. VPN access should use strong authentication, MFA, current software, monitoring, and appropriate access controls.

Can Remote Desktop be brute forced?

Publicly reachable Remote Desktop services can receive automated authentication attempts. Direct exposure should be carefully controlled, and secure remote access architecture should be used.

Can SSH be brute forced?

Publicly accessible SSH services can receive automated authentication attempts. SSH should use appropriate authentication, exposure controls, updates, and monitoring.

Can a firewall be brute forced?

A publicly reachable firewall management or authentication service may receive password guessing attempts. Administrative interfaces should be strongly protected and not exposed more broadly than necessary.

What does repeated failed login activity mean?

It may indicate user error, stale credentials, application problems, password guessing, password spraying, or other activity. The pattern and context should be investigated.

How many failed logins indicate an attack?

There is no universal number. The appropriate threshold depends on the application, number of users, normal behavior, and security architecture.

What is account lockout?

Account lockout temporarily or permanently restricts authentication after a defined number of unsuccessful attempts.

Does account lockout stop brute force attacks?

It can reduce password guessing, but lockout settings must balance security and availability. Attackers may also distribute attempts across accounts or addresses.

What is rate limiting?

Rate limiting restricts how frequently authentication attempts or other requests can occur, making automated attacks slower and less efficient.

Should I block IP addresses attempting brute force attacks?

Blocking clearly malicious addresses can help, but attackers can use many addresses. Blocking should complement stronger controls such as MFA, secure exposure, rate limiting, and monitoring.

How can I tell whether a brute force attack succeeded?

Review authentication logs for successful logins following suspicious failures and investigate the account's subsequent activity.

What should I do if a brute force attack succeeds?

Follow the organization's incident response procedures. Actions may include containment, credential changes, session revocation, account review, log analysis, investigation of subsequent activity, and appropriate escalation.

Are brute force attacks only a problem for large businesses?

No. Automated attacks do not require an attacker to specifically select a large organization. Any accessible login can potentially receive automated attempts.

Do attackers know which company they are attacking?

Not necessarily. Automated tools may discover exposed authentication services and begin testing them without extensive knowledge of the organization operating them.

Sources

Editorial note

Cybersecurity risk and the controls appropriate to it vary by organization. Evaluate these recommendations against your own technology environment, business requirements, regulatory obligations, threat profile and risk tolerance.

USA Telecom Consulting LLC is a Service-Disabled Veteran-Owned Small Business running a 24/7 NOC. We monitor networks, circuits and firewalls for regulated and defense-supply-chain organizations.

← More from the ADAM Pulse Knowledge Base