When somebody systematically tries to guess a password, they leave traces. Not always obvious ones, but almost always observable — if you know where to look.
That is an important difference from other scenarios: here the signals arrive before the attempt succeeds. They are a warning, not a finding. And a warning about a weak password is exactly the moment to replace it.
This post collects the indicators of compromise connected to attempts at guessing or forcing a password. It expands on the recommendation sixteen character passwords.
Two kinds of signal, two different meanings
Telling them apart is the most useful part.
Signs of an attempt under way. Somebody is trying, and has not yet succeeded: failed attempts, temporary lockouts, unexpected verification requests. These are the most valuable, because they arrive while there is still time.
Signs of a successful attempt. Somebody is in: a password that no longer works, altered recovery details, activity you do not recognise. Here you move from prevention to response.
From which the rule of thumb: a signal of the first kind on a weak password should be treated as though the second were imminent. There is no need to wait for confirmation.
Technical indicators
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| Repeated failed sign-in attempts | Somebody is trying combinations on your account | The most direct sign of an attempt under way | Service notifications, security section, access log | Replace the password with a long one; turn on the second factor |
| Temporary account lockout | The service detected too many attempts and suspended access | The protection worked, but somebody was trying | Login message, security email | Change the password before unlocking; do not reuse a similar one |
| Unexpected additional verification request | The service asks for an extra check because the sign-in looks unusual to it | Indicates an attempt from a context other than yours | Login screen, notification | Do not complete it if it is not you; change the password |
| Sign-ins from unrecognised places or devices | An attempt succeeded, or came close | Signals that the password may already be known | Access history, connected devices | Change the password, revoke sessions, check recovery details |
| Alert that a password appeared in a breach | That password circulates in public lists | From that moment it is no longer a password, it is known data | Vault, browser or system notifications | Replace it everywhere you had used it, not just there |
| “Password too common” notice | The service recognised a very widespread combination | Common passwords are the first to be tried | At registration or when changing it | Rewrite it with the word method |
| Changes to recovery details | Somebody changed the associated email or phone | This is the step that keeps their access and locks you out | Confirmation emails, account settings | Act at once: undo if possible, change the password, contact support |
Signs you can observe yourself
| Signal | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| The correct password no longer works | It has been changed by somebody else | The attempt succeeded | You cannot sign in even though you typed it right | Start recovery through official channels, beginning with email |
| Reset emails you did not request | Somebody is attempting recovery, or it is phishing | Either way it deserves checking | You receive a reset message you never started | Do not click the links; go in through the official site and check |
| Messages sent from your account | The account is being used to communicate with others | It exposes your contacts to scams run in your name | Contacts telling you about it | Change the password, revoke sessions, warn your contacts |
| Activity or purchases you do not recognise | The account has been used for transactions | Financial loss or misuse of your data | Orders, charges or changes you did not make | Contact the service, check payment methods, change the password |
| Somebody knows things you never shared | Possible access to your mail or archives | The least technical and most concrete signal | A conversation in which a private detail surfaces | Check sign-ins and forwarding rules on your email |
| Your email address appears in a breach | A service you had signed up to was breached | The password used there must be treated as public | Check on a well-known service, entering only the address | Change it on that service and everywhere you had reused it |
A concrete example
Helen receives, over one week, three emails from her mail provider: “failed sign-in attempt”.
She files the first two — it happens. At the third she becomes suspicious and looks at the security section: fourteen failed attempts in six days, from different places.
Nobody got in. But her password was Helen1987! — name and year of birth, both derivable from her public profile.
She changes it to four unconnected words and turns on the second factor. The attempts continue for another couple of weeks, and all of them fail.
The lesson: the signals had arrived on day one. The value of recognising them lies in the fact that, when they arrive, there is still time.
What to check, and how often
| Frequency | What to check |
|---|---|
| Whenever a notification arrives | Check immediately, and do not file failed-attempt alerts without reading them |
| Every 2–3 months | Recent sign-ins, connected devices, active sessions on your main accounts |
| Every 6 months | Analysis of weak and duplicated passwords; recovery details up to date |
| After a breach alert | Every service where you had used that password |
| When you create a new account | That the password meets 16 characters and does not derive from another |
Where these signals live
Section names vary from service to service, but the information is almost always the same.
| What you are looking for | What it is usually called | What it tells you |
|---|---|---|
| Who signed in and from where | “Recent activity”, “Sign-in history”, “Security” | Whether somebody got in, and from what context |
| Failed attempts | “Login attempts”, email notifications | Whether somebody is trying — the most valuable signal |
| Devices and sessions | “Connected devices”, “Active sessions” | Whether an access is still open |
| Recovery details | “Security settings”, “Account recovery” | Whether somebody altered them |
| Exposed passwords | Vault analysis, browser alerts | Whether one of your credentials is circulating publicly |
It is worth knowing that not every service offers all five. In particular, notifications about failed attempts are less common than people think: where they exist, they are worth keeping on and reading.
Why these alerts get ignored
This is where the value of this post really lies, so it deserves addressing.
Failed-attempt alerts arrive by email, often with a subject line resembling the service’s promotional messages. They get read distractedly, filed and forgotten — for three understandable reasons:
- nothing happened. The attempt failed: it looks like a non-event;
- they arrive in isolation. One a week does not build a picture;
- they look like phishing. Anyone trained to distrust security alerts will, out of caution, not open them.
The last reason is the most insidious, because it comes from the right instinct. The solution is not to click the links: it is to check inside the account, going in through the app or the address you normally use.
A rule of thumb valid in all three cases: when you get a failed-attempt alert, do not reply to the message — go to the service’s security section and see how many there have been. If there are more than two or three within a few weeks, that password has to change today.
What is not an indicator
| Situation | Why it is usually not a signal |
|---|---|
| A single failed attempt | Often one of your own devices with the old password saved |
| The service asks for verification after a trip | The context changed: that is the protection working |
| An “exposed password” alert right after changing it | It refers to the previous password, not the new one |
| Unusual promotional emails | They indicate the address is circulating on marketing lists |
| The vault flagging a password as “weak” with no incident | That is preventive analysis, not the detection of an attack |
The rule stands: one isolated signal deserves a check; two together deserve action.
If you find an indicator
- Do not complete verifications or approvals you did not start.
- Change the password, rewriting it from scratch — not editing the old one.
- Turn on the second factor, if it is not already on: it is the measure that holds even if the password is obtained anyway.
- Revoke unrecognised sessions and devices, after the password change.
- Check the recovery details: secondary email, phone, security questions.
- Look at where you had used that password or a variant of it, and change it there too.
The full sequence is in how to make a password long enough.
Two warnings
The absence of signals does not mean the password is strong. Many attempts generate no notification, and not every service offers them. Protection rests on the length of the password, not on watching for alerts.
Beware of fake alerts. “Suspicious sign-in attempt” notifications are among the most imitated by phishing, precisely because they push people to act quickly. No legitimate service asks for your password in order to “verify your security”. Always go in through the app or the address you normally use, never through a link you received.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Reading an account’s security sections and telling an attempt from a success |
| Awareness | Understanding that a failed attempt is a warning, not a non-event |
| Secure Behaviour | Reacting at the first signal, while there is still time |
Reference level: FL3 — Autonomous.
Conclusion
Attempts at guessing a password produce signals in advance. That is a rare advantage in digital security, and it is squandered almost always for the same reason: those alerts get filed without being read.
What to do right now. Search your mailbox for security alerts from the last few months. If you find even one failed-attempt notice on an important account, that password has to change today.
Related content
- Sixteen character passwords — the recommendation this belongs to
- Password guessing attacks — what generates these signals
- How to make a password long enough — what to do when you find one
- The impact of a weak password — what gets hit if the attempt succeeds
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



