CYBER WELFARE

Protect your Digital Privacy

Password guessing attacks: how they work and what stops them

When people talk about “guessed” passwords, the image that comes to mind is somebody trying random combinations until one works. That is the furthest thing from reality.

Nobody starts from random combinations. They start from what people actually do: common words, names, dates, known substitutions, the year at the end. And they proceed in order of probability.

Understanding this changes how you choose a password — far more than any rule about special characters. This post describes the attacks from the point of view of the person on the receiving end, so they can be recognised and defended against; it contains no operational instructions.

It is the threat-side companion to the recommendation sixteen character passwords.

Two very different settings

First of all, a distinction that decides almost everything.

Against the live service. Attempts go through the site’s or app’s login. They are slow by design: after a few errors come slowdowns, extra checks, temporary lockouts. Here even a mediocre password holds for a long time.

Against a stolen store. A service has been breached and the sign-in data is in someone else’s hands. Attempts happen without passing any control, and there can be a great many of them. This is the scenario a long password is for, and it is also the one you cannot control.

Keeping this difference in mind explains why length really counts in only one case — but it is the case in which you have no other defence.

1. Dictionary attack

In plain terms. Real words and their most common variants get tried, instead of random combinations.

How it works. It starts from lists of everyday words, first names, cities, teams, and applies the typical transformations: capital at the front, number at the end, a swapped for @, o for 0, an exclamation mark to finish.

Why it is effective. Because it describes exactly the way most passwords are built. London2026! does not need to be guessed: it falls inside an anticipated pattern.

Possible impact. Access to the account, with all the effects described in the impact of a weak password.

What should make you suspicious. Failed sign-in attempts, temporary lockouts, unexpected verification requests.

How to protect yourself. Do not start from a word. Four unconnected words are on no list, because it is the combination that counts, not the individual words.

2. Systematic attempts (brute force)

In plain terms. Trying every possible combination, in order, until one works.

How it works. It is the most expensive approach and the least used as a first move, precisely because the number of possibilities grows explosively with length. It becomes practical only against short passwords, and almost exclusively against a stolen store.

Why length stops it. Every character added multiplies the number of combinations to try. That is the technical reason behind the sixteen-character threshold, explained in what makes a password hard to guess.

Possible impact. Compromise of accounts with short passwords, especially older ones.

What should make you suspicious. Against the live service: many failed attempts, repeated lockouts. Against a stolen store: no signal at all, until the account gets used.

How to protect yourself. Length, before anything else. Then the second factor.

3. Attack based on personal data

In plain terms. Attempts get built from what is known about you.

How it works. Names of family members and pets, birthdays and anniversaries, towns, favourite team, company name: much of this is public on social profiles, or findable through a search.

Why it works. Because passwords built on personal details are among the most widespread — precisely because they are the ones people remember.

Possible impact. Access to personal accounts and, if the same logic was used at work, to professional ones too.

What should make you suspicious. Targeted attempts, often few and close together, sometimes accompanied by password recovery requests.

How to protect yourself. No detail concerning you inside your passwords. And, as a complementary measure, reduce the personal information visible on your public profiles — that is worth doing for other reasons too.

4. Password spraying

In plain terms. Instead of trying many passwords against one account, one very common password is tried against a great many accounts.

How it works. It starts from the most widespread combinations — seasons with the year, city names, keyboard sequences — and tries each user just once. By trying little against each, the automatic lockouts are avoided.

Why it is insidious. It does not generate the usual signals of an attack: a single failed attempt per account goes unnoticed.

Possible impact. In organisations, a way in towards internal systems. For individuals, access to services with common passwords.

What should make you suspicious. A single isolated failed attempt, which often gets ignored precisely because it is isolated.

How to protect yourself. A long, uncommon password is by definition outside the lists used in this kind of attempt. Plus the second factor.

5. Password reuse (credential stuffing)

In plain terms. Nothing is guessed: a password already stolen elsewhere is simply tried again.

How it works. Lists of credentials taken from one service get tried automatically against many others.

Why it belongs here. Because no amount of length protects against this. A forty-character password, reused on a service that gets breached, is worth the same as an eight-character one.

Possible impact. Access to every service where that password was in use.

What should make you suspicious. Sign-ins from unusual places, compromised-password alerts.

How to protect yourself. This is the domain of recommendation R1: uniqueness. Length and uniqueness are two distinct requirements and both are needed.

6. Phishing

In plain terms. The password is not guessed: somebody is convinced to type it on a fake page.

How it works. A credible message leads to a copy of the real site. What you type reaches whoever built the page.

Why it belongs here. Because it is the method that makes every discussion of strength irrelevant. Against a password handed over voluntarily, length has no effect at all.

What should make you suspicious. Unjustified urgency, a sender address that does not match, a similar but not identical domain, a request for credentials by message. And the most reliable signal of all: the password vault does not autofill on that page.

How to protect yourself. Never sign in from links you received. Use a vault, which compares the address. Turn on the second factor.

7. Direct observation

In plain terms. Somebody sees the password while you type it, or finds it written down.

How it works. A keyboard watched on a train or in a shared office, a sheet of paper under the keyboard, an unprotected note on a phone, a password read out over the telephone.

Why it concerns complex passwords in particular. It is a rarely discussed side effect: the harder a password is to remember, the more likely it is to be written down. Rigid complexity rules produce exactly this behaviour.

What should make you suspicious. Sign-ins from places you frequent; the sense that somebody knows things you never shared.

How to protect yourself. A memorable password — long, but built on words — does not need writing down. For all the others, the vault. And pay attention to who is around when you type.

Summary table

AttackWhat makes it effectiveWhat should make you suspiciousMain defence
DictionaryPasswords built on common wordsFailed attempts, lockoutsMultiple unconnected words
Brute forceShort passwordsRepeated attempts, or no signal at allLength (16+ characters)
Personal dataPublic information on profilesTargeted attempts, recovery requestsNo personal details in passwords
Password sprayingVery common passwordsA single isolated failed attemptAn uncommon password + MFA
Credential reuseThe same password on several servicesUnusual sign-ins, exposure alertsUniqueness (R1)
PhishingVoluntary handoverUrgency, similar domain, the vault does not autofillSign in only from official addresses
Direct observationPasswords written down because they are hardSign-ins from places you frequentA memorable password, or a vault

The order things get tried in

One aspect clarifies almost everything else: whoever tries to guess a password does not proceed at random, they proceed in decreasing order of probability.

The typical order is this:

  1. The most widespread passwords of all. Number sequences, very common words, team and city names. A few thousand combinations cover a surprising share of accounts.
  2. The same ones, with the standard transformations. Capital at the front, year at the end, exclamation mark to finish, known substitutions.
  3. Dictionary words, with the same transformations.
  4. Personal details taken from public profiles, combined with each other.
  5. Credentials already known from previous breaches, tried exactly as they are.
  6. Only at the end, and rarely, systematic combinations.

The practical consequence is clear-cut: a password that does not fall into the first five groups is already beyond the practical reach of these attempts. You do not need to be unbeatable — you need to not be on the list.

Four unconnected words fall into none of the five groups. They are not a common word, they do not derive from a standard transformation, they have no relationship to you, and they have never appeared on a list.

Why time works in your favour, but only in one case

Against live services, time is an ally: each attempt costs seconds, lockouts accumulate, and whoever is trying moves on to easier targets.

Against a stolen store, time does not help: attempts run in parallel and without limits, and can continue for months without anyone noticing.

Two different behaviours follow:

  • for everyday sign-in, what counts most is that the password is not a common one and that the second factor is on;
  • for the stolen-store scenario, length is what counts — and it is the only defence you have, because everything else is in the hands of the breached service.

That is why the recommendation speaks of a minimum number of characters and not of “a password the site accepts”.

What they have in common

Looking at the table, one thing emerges that is worth more than any single defence: only two attacks out of seven are stopped by length alone.

The others require the neighbouring recommendations:

  1. Length — this recommendation: stops brute force and dictionary attacks.
  2. Uniqueness — R1: stops credential reuse.
  3. The second factor — R4: steps in when the password has been obtained anyway, in every scenario.

The three together cover the entire table. None of them, alone, gets there.

And there is a detail worth noticing: memorability is a security measure, not a compromise. A password that never has to be written down removes an entire scenario.

Protection checklist

  • ☐ My important passwords exceed 16 characters
  • ☐ They do not derive from a common word, not even a modified one
  • ☐ They contain no names, dates, places or references connected to me
  • ☐ They are not variants of one another
  • ☐ None of them is written on paper or in an unprotected note
  • ☐ The second factor is enabled on email, bank, cloud and work
  • ☐ I reach services from the app or the usual address, never from links I received
  • ☐ I have checked which personal details are visible on my public profiles

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that nobody starts from random combinations, but from people’s habits
SkillsRecognising which defence is needed against which kind of attempt
Secure BehaviourChoosing passwords that never need writing down

Reference level: FL2 — Beginner, with elements of FL3 — Autonomous in the spraying and reuse sections.

Conclusion

Whoever tries to guess a password does not begin with aaaaaaaa. They begin with names, with dates, with seasons and the year, with the substitutions everybody knows.

That is why the defence is not to complicate: it is to step outside the predictable. Four words with no relationship to each other are on no list, derive from nothing about you, and need to be written down nowhere.

Something to think about. If somebody read your public profiles for ten minutes, how many of the details they found would appear in your passwords?

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.