Delinea Blog > Types of brute force attacks and how to prevent them

Types of brute force attacks and how to prevent them

Published August 2022
Read time 6 minutes
What you will learn
Explore how brute force attacks work, from dictionary attacks to credential stuffing. See the tools and hardware behind them, how they differ from related attacks, and how to reduce risk with MFA and passwordless authentication. 

Brute force attacks don't need to be sophisticated. They need to be fast. Twelve consumer graphics cards, about $48,000 of hardware you can order online, can crack an eight-character numbers-only password in about 15 minutes. It's a machine making guesses until one fits. 

They're also getting more common. The Verizon 2025 Data Breach Investigations Report (DBIR) found brute force attempts in basic web applications jumped from around 20% to 60% in a single year. They keep working because the bar is so low: one weak password and enough attempts.   

What is a brute force attack?

A brute force attack is a cyberattack in which a cybercriminal guesses usernames and passwords by trial and error until one combination gets them into an account or network. The name comes from the method: repeated attempts, or "force," until something gives. 

Simple vs. automated brute force attack

Brute force is one of the oldest cybercrime tactics, and it still works. The manual version is one person typing guesses, working from common passwords or details they already know about the target.

Automation changed that. Brute force tools now generate and try millions of passwords in seconds. The Verizon DBIR puts credential abuse at 22% of all breaches, the most common initial access vector. 

Why brute force attacks work

Cybercriminals count on weak passwords: short, memorable and missing the mix of cases, numbers and symbols that slows guessing down.

In 2024, 2.8 billion passwords were posted for sale or for free on criminal message boards, encrypted messenger groups and darknet markets

Passwords often include personal details anyone can find online: a name, a birth year, a favorite team. If a cybercriminal sees on Facebook that you were born in 1990 and follow the Chicago Bears, "Bears 1990" goes on the list. "123456" is one of the most commonly used passwords in the world, making it an easy choice for a cybercriminal.

Once inside, the cybercriminal can steal proprietary data, sell it on the dark web, hold systems for ransom or spread malware across the network, whether for economic, social or political reasons.

Different types of brute force attacks

A brute force attack is a category as much as a method. The variations differ in what the cybercriminal starts with: a username, a list of likely passwords, a known password or a working set of credentials from another breach.

The main variations:

  • Traditional brute force attacks. The simplest method. A cybercriminal has a username or list of usernames and guesses passwords, manually or by running a script, until the correct combination is found. 
  • Dictionary attacks. A cybercriminal runs a pre-made list of passwords against a specific username. The list, or "dictionary," is built from common passwords, slight variations on them and words drawn from research on the target.
  • Hybrid attacks. A combination of traditional and dictionary attacks. The cybercriminal takes the most common words and phrases from the dictionary and tries variations of each, adding numbers, symbols or capital letters. 
  • Reverse brute force attacks. A cybercriminal starts with a known password, either acquired from a breach or commonly used, and tries it against multiple usernames until a match is found. It's the traditional attack worked backward: known password, unknown username. 
  • Credential stuffing. A cybercriminal already has a working username and password for one system and uses the same credentials to access the user's other accounts. This works because people frequently reuse passwords.

Brute force attack tools

Brute force tools automate the guessing. They generate password combinations, run dictionary attacks, crack password hashes and flag weak passwords across many protocols and operating systems.

Some of the most popular tools:

  • John the Ripper. Open-source software for running dictionary attacks and detecting weak passwords.
  • Aircrack-ng. An open-source suite for testing Wi-Fi security, including dictionary attacks against wireless network keys. 
  • Hashcat. A password-recovery tool that works on stolen password hashes (a password run through a formula that turns it into a fixed-length string of characters). With the hashes in hand, Hashcat runs dictionary or rainbow-table attacks to recover the password as readable text.

Brute force hardware

These tools are only as fast as the hardware behind them. A single central processing unit (CPU) is too slow to crack a strong password in a useful amount of time. So cybercriminals can run their tools on graphics processing units (GPUs), which test thousands of guesses in parallel.

Online vs. offline brute force attacks

In an online attack, the cybercriminal guesses directly against the live login page or network. That limits them: most systems lock an account after a set number of failed attempts, and each guess must wait for a response. 

Offline attacks get around that. The cybercriminal steals a copy of the password database, which stores hashes rather than plain-text passwords, and runs the cracking tool against it on their own hardware. No logins, no lockouts and no limit on speed except the hardware. 

Brute force attacks vs. other cyberattacks

Brute force attacks vs. dictionary attacks

A dictionary attack is a type of brute force attack; the difference is scope. Traditional brute force tries every possible combination of characters. A dictionary attack tries only a curated list of likely passwords, which is faster when the target's password is predictable. 

Brute force attacks vs. password spraying

Password spraying reverses the approach. One common password is tried against many accounts, rather than many passwords against one account. Spreading attempts across accounts keeps each one under the lockout threshold.

Brute force attacks vs. DoS

A denial-of-service (DoD) attack overloads a server with traffic or service requests until it shuts down. Brute force, by contrast, is about getting in, not taking down. The two can connect: a cybercriminal might brute force their way into a server, then launch a DoS attack from the inside. 

Brute force attacks vs. DDoS

A distributed denial-of-service (DDoS) attack is a DoS attack launched from many machines at once, which makes it much harder to block. The same distinction applies: DDoS takes a system offline, while brute force gets a cybercriminal into it. 

Brute force attacks vs. credential stuffing

Credential stuffing uses credentials stolen from one system to log in to others. It relies on reuse rather than guessing, which is why it's often the result of a successful brute force attack. It also works at scale: the Verizon DBIR found 88% of attacks against basic web applications involved stolen credentials. 

How to prevent brute force attacks

Brute force attacks depend on weak credentials, so start there: require long, complex passwords and block the most common ones. 

Set lockout policies on internal and external applications so an account freezes after multiple failed attempts. You can also use zero trust best practices, such as multi-factor authentication (MFA), to require additional authentication.   

Brute force only works against "something you know," like a password or pin. Remove the password and there's nothing to guess. Passwordless authentication replaces it with biometrics, such as facial recognition, or a hardware token.

How Delinea reduces brute force risk

Secret Server vaults privileged credentials and rotates them on a schedule or on demand. It injects them directly into sessions, so the person connecting never sees or types them. A password that's never typed can't be guessed at a login prompt.

Enforce MFA at login and again at privilege elevation. Privileged Remote Access gives employees and third parties browser-based access to servers and databases with no internet-facing login for cybercriminals to guess. Just-in-time access, instead of standing access, shrinks the window in which a guessed credential is worth anything.

All of it runs on the Delinea Platform , which integrates with your identity provider for centralized authentication and authorization.

Related Topics