CYBER WELFARE

Protect your Digital Privacy

Signs your password is under attack: what to watch

When somebody systematically tries to guess a password, they leave traces. Not always obvious ones, but almost always observable — if you know where to look.

That is an important difference from other scenarios: here the signals arrive before the attempt succeeds. They are a warning, not a finding. And a warning about a weak password is exactly the moment to replace it.

This post collects the indicators of compromise connected to attempts at guessing or forcing a password. It expands on the recommendation sixteen character passwords.

Two kinds of signal, two different meanings

Telling them apart is the most useful part.

Signs of an attempt under way. Somebody is trying, and has not yet succeeded: failed attempts, temporary lockouts, unexpected verification requests. These are the most valuable, because they arrive while there is still time.

Signs of a successful attempt. Somebody is in: a password that no longer works, altered recovery details, activity you do not recognise. Here you move from prevention to response.

From which the rule of thumb: a signal of the first kind on a weak password should be treated as though the second were imminent. There is no need to wait for confirmation.

Technical indicators

IndicatorWhat it meansWhy it mattersWhere you see itWhat to do
Repeated failed sign-in attemptsSomebody is trying combinations on your accountThe most direct sign of an attempt under wayService notifications, security section, access logReplace the password with a long one; turn on the second factor
Temporary account lockoutThe service detected too many attempts and suspended accessThe protection worked, but somebody was tryingLogin message, security emailChange the password before unlocking; do not reuse a similar one
Unexpected additional verification requestThe service asks for an extra check because the sign-in looks unusual to itIndicates an attempt from a context other than yoursLogin screen, notificationDo not complete it if it is not you; change the password
Sign-ins from unrecognised places or devicesAn attempt succeeded, or came closeSignals that the password may already be knownAccess history, connected devicesChange the password, revoke sessions, check recovery details
Alert that a password appeared in a breachThat password circulates in public listsFrom that moment it is no longer a password, it is known dataVault, browser or system notificationsReplace it everywhere you had used it, not just there
“Password too common” noticeThe service recognised a very widespread combinationCommon passwords are the first to be triedAt registration or when changing itRewrite it with the word method
Changes to recovery detailsSomebody changed the associated email or phoneThis is the step that keeps their access and locks you outConfirmation emails, account settingsAct at once: undo if possible, change the password, contact support

Signs you can observe yourself

SignalWhat it meansWhy it mattersHow you noticeWhat to do
The correct password no longer worksIt has been changed by somebody elseThe attempt succeededYou cannot sign in even though you typed it rightStart recovery through official channels, beginning with email
Reset emails you did not requestSomebody is attempting recovery, or it is phishingEither way it deserves checkingYou receive a reset message you never startedDo not click the links; go in through the official site and check
Messages sent from your accountThe account is being used to communicate with othersIt exposes your contacts to scams run in your nameContacts telling you about itChange the password, revoke sessions, warn your contacts
Activity or purchases you do not recogniseThe account has been used for transactionsFinancial loss or misuse of your dataOrders, charges or changes you did not makeContact the service, check payment methods, change the password
Somebody knows things you never sharedPossible access to your mail or archivesThe least technical and most concrete signalA conversation in which a private detail surfacesCheck sign-ins and forwarding rules on your email
Your email address appears in a breachA service you had signed up to was breachedThe password used there must be treated as publicCheck on a well-known service, entering only the addressChange it on that service and everywhere you had reused it

A concrete example

Helen receives, over one week, three emails from her mail provider: “failed sign-in attempt”.

She files the first two — it happens. At the third she becomes suspicious and looks at the security section: fourteen failed attempts in six days, from different places.

Nobody got in. But her password was Helen1987! — name and year of birth, both derivable from her public profile.

She changes it to four unconnected words and turns on the second factor. The attempts continue for another couple of weeks, and all of them fail.

The lesson: the signals had arrived on day one. The value of recognising them lies in the fact that, when they arrive, there is still time.

What to check, and how often

FrequencyWhat to check
Whenever a notification arrivesCheck immediately, and do not file failed-attempt alerts without reading them
Every 2–3 monthsRecent sign-ins, connected devices, active sessions on your main accounts
Every 6 monthsAnalysis of weak and duplicated passwords; recovery details up to date
After a breach alertEvery service where you had used that password
When you create a new accountThat the password meets 16 characters and does not derive from another

Where these signals live

Section names vary from service to service, but the information is almost always the same.

What you are looking forWhat it is usually calledWhat it tells you
Who signed in and from where“Recent activity”, “Sign-in history”, “Security”Whether somebody got in, and from what context
Failed attempts“Login attempts”, email notificationsWhether somebody is trying — the most valuable signal
Devices and sessions“Connected devices”, “Active sessions”Whether an access is still open
Recovery details“Security settings”, “Account recovery”Whether somebody altered them
Exposed passwordsVault analysis, browser alertsWhether one of your credentials is circulating publicly

It is worth knowing that not every service offers all five. In particular, notifications about failed attempts are less common than people think: where they exist, they are worth keeping on and reading.

Why these alerts get ignored

This is where the value of this post really lies, so it deserves addressing.

Failed-attempt alerts arrive by email, often with a subject line resembling the service’s promotional messages. They get read distractedly, filed and forgotten — for three understandable reasons:

  • nothing happened. The attempt failed: it looks like a non-event;
  • they arrive in isolation. One a week does not build a picture;
  • they look like phishing. Anyone trained to distrust security alerts will, out of caution, not open them.

The last reason is the most insidious, because it comes from the right instinct. The solution is not to click the links: it is to check inside the account, going in through the app or the address you normally use.

A rule of thumb valid in all three cases: when you get a failed-attempt alert, do not reply to the message — go to the service’s security section and see how many there have been. If there are more than two or three within a few weeks, that password has to change today.

What is not an indicator

SituationWhy it is usually not a signal
A single failed attemptOften one of your own devices with the old password saved
The service asks for verification after a tripThe context changed: that is the protection working
An “exposed password” alert right after changing itIt refers to the previous password, not the new one
Unusual promotional emailsThey indicate the address is circulating on marketing lists
The vault flagging a password as “weak” with no incidentThat is preventive analysis, not the detection of an attack

The rule stands: one isolated signal deserves a check; two together deserve action.

If you find an indicator

  1. Do not complete verifications or approvals you did not start.
  2. Change the password, rewriting it from scratch — not editing the old one.
  3. Turn on the second factor, if it is not already on: it is the measure that holds even if the password is obtained anyway.
  4. Revoke unrecognised sessions and devices, after the password change.
  5. Check the recovery details: secondary email, phone, security questions.
  6. Look at where you had used that password or a variant of it, and change it there too.

The full sequence is in how to make a password long enough.

Two warnings

The absence of signals does not mean the password is strong. Many attempts generate no notification, and not every service offers them. Protection rests on the length of the password, not on watching for alerts.

Beware of fake alerts. “Suspicious sign-in attempt” notifications are among the most imitated by phishing, precisely because they push people to act quickly. No legitimate service asks for your password in order to “verify your security”. Always go in through the app or the address you normally use, never through a link you received.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsReading an account’s security sections and telling an attempt from a success
AwarenessUnderstanding that a failed attempt is a warning, not a non-event
Secure BehaviourReacting at the first signal, while there is still time

Reference level: FL3 — Autonomous.

Conclusion

Attempts at guessing a password produce signals in advance. That is a rare advantage in digital security, and it is squandered almost always for the same reason: those alerts get filed without being read.

What to do right now. Search your mailbox for security alerts from the last few months. If you find even one failed-attempt notice on an important account, that password has to change today.

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.