Brute force attacks don't need to be sophisticated. They need to be fast. Twelve consumer graphics cards, about $48,000 of hardware you can order online, can crack an eight-character numbers-only password in about 15 minutes. It's a machine making guesses until one fits.
They're also getting more common. The Verizon 2025 Data Breach Investigations Report (DBIR) found brute force attempts in basic web applications jumped from around 20% to 60% in a single year. They keep working because the bar is so low: one weak password and enough attempts.
A brute force attack is a cyberattack in which a cybercriminal guesses usernames and passwords by trial and error until one combination gets them into an account or network. The name comes from the method: repeated attempts, or "force," until something gives.
Brute force is one of the oldest cybercrime tactics, and it still works. The manual version is one person typing guesses, working from common passwords or details they already know about the target.
Automation changed that. Brute force tools now generate and try millions of passwords in seconds. The Verizon DBIR puts credential abuse at 22% of all breaches, the most common initial access vector.
Cybercriminals count on weak passwords: short, memorable and missing the mix of cases, numbers and symbols that slows guessing down.
In 2024, 2.8 billion passwords were posted for sale or for free on criminal message boards, encrypted messenger groups and darknet markets
Passwords often include personal details anyone can find online: a name, a birth year, a favorite team. If a cybercriminal sees on Facebook that you were born in 1990 and follow the Chicago Bears, "Bears 1990" goes on the list. "123456" is one of the most commonly used passwords in the world, making it an easy choice for a cybercriminal.
Once inside, the cybercriminal can steal proprietary data, sell it on the dark web, hold systems for ransom or spread malware across the network, whether for economic, social or political reasons.
A brute force attack is a category as much as a method. The variations differ in what the cybercriminal starts with: a username, a list of likely passwords, a known password or a working set of credentials from another breach.
The main variations:
Brute force tools automate the guessing. They generate password combinations, run dictionary attacks, crack password hashes and flag weak passwords across many protocols and operating systems.
Some of the most popular tools:
These tools are only as fast as the hardware behind them. A single central processing unit (CPU) is too slow to crack a strong password in a useful amount of time. So cybercriminals can run their tools on graphics processing units (GPUs), which test thousands of guesses in parallel.
In an online attack, the cybercriminal guesses directly against the live login page or network. That limits them: most systems lock an account after a set number of failed attempts, and each guess must wait for a response.
Offline attacks get around that. The cybercriminal steals a copy of the password database, which stores hashes rather than plain-text passwords, and runs the cracking tool against it on their own hardware. No logins, no lockouts and no limit on speed except the hardware.
A dictionary attack is a type of brute force attack; the difference is scope. Traditional brute force tries every possible combination of characters. A dictionary attack tries only a curated list of likely passwords, which is faster when the target's password is predictable.
Password spraying reverses the approach. One common password is tried against many accounts, rather than many passwords against one account. Spreading attempts across accounts keeps each one under the lockout threshold.
A denial-of-service (DoD) attack overloads a server with traffic or service requests until it shuts down. Brute force, by contrast, is about getting in, not taking down. The two can connect: a cybercriminal might brute force their way into a server, then launch a DoS attack from the inside.
A distributed denial-of-service (DDoS) attack is a DoS attack launched from many machines at once, which makes it much harder to block. The same distinction applies: DDoS takes a system offline, while brute force gets a cybercriminal into it.
Credential stuffing uses credentials stolen from one system to log in to others. It relies on reuse rather than guessing, which is why it's often the result of a successful brute force attack. It also works at scale: the Verizon DBIR found 88% of attacks against basic web applications involved stolen credentials.
Brute force attacks depend on weak credentials, so start there: require long, complex passwords and block the most common ones.
Set lockout policies on internal and external applications so an account freezes after multiple failed attempts. You can also use zero trust best practices, such as multi-factor authentication (MFA), to require additional authentication.
Brute force only works against "something you know," like a password or pin. Remove the password and there's nothing to guess. Passwordless authentication replaces it with biometrics, such as facial recognition, or a hardware token.
Secret Server vaults privileged credentials and rotates them on a schedule or on demand. It injects them directly into sessions, so the person connecting never sees or types them. A password that's never typed can't be guessed at a login prompt.
Enforce MFA at login and again at privilege elevation. Privileged Remote Access gives employees and third parties browser-based access to servers and databases with no internet-facing login for cybercriminals to guess. Just-in-time access, instead of standing access, shrinks the window in which a guessed credential is worth anything.
All of it runs on the Delinea Platform , which integrates with your identity provider for centralized authentication and authorization.