A brute force attack is an attempt to get into an account by guessing the login details over and over, automatically, until one works. Software never tires and can keep trying day and night, so a short or reused password on your website, email or hosting account can fall far sooner than most people expect.
How a brute force attack works
There are a few variations, and they are often combined:
- Pure guessing works through every possible combination. It is slow against long passwords and quick against short ones.
- Dictionary attacks try common passwords and their predictable variants, such as a word with a capital letter and “1!” on the end.
- Credential stuffing uses email and password pairs leaked from other websites’ breaches. It works because so many people reuse the same password.
- Password spraying tries one popular password against many different accounts, which avoids tripping lockouts on any single one.
Attackers aim at whatever is public. On a WordPress site that means the login page and the XML-RPC file, which accepts login attempts too. Hosting control panels, business email accounts and website staff accounts are all targets, and most attacks are fully automated scans looking for any weak site, not a deliberate choice of yours.
Why it matters
A successful break-in gives the attacker your site. Common results are hidden spam pages, links to dubious sites, redirects that send your visitors elsewhere, or malicious code that infects them. Google may label the site as hacked in its results, and the Security Issues report in Search Console will show the problem. Cleaning up and recovering search visibility takes time and money.
If the account holds customer details, it is a personal data breach too. Under UK GDPR you must report a breach to the ICO within 72 hours of becoming aware of it, unless it is unlikely to put people at risk. Even attacks that fail cost you something, because thousands of login attempts load the server and can slow the site for real visitors.
The UK’s National Cyber Security Centre publishes free, practical guidance for small organisations on passwords, password managers and two-step verification, and is the best place to start if you want the official view.
Common mistakes
- Keeping a login called “admin” or using the business name as the username.
- Reusing one password across the website, email and hosting, so a single leak opens everything.
- Sharing one administrator login among staff and freelancers instead of giving each person their own.
- Relying on a renamed login page alone. It reduces noise but does not stop a determined attempt.
- Protecting the website carefully while leaving the email account, which can reset every other password, without two-step verification.
How to act on it
Give every person their own account with only the rights they need, and remove accounts the moment someone leaves. Use long, unique passwords stored in a password manager; three random words joined together is easy to remember and hard to guess.
Turn on two-factor authentication for the website admin, hosting, domain registrar and, above all, business email. Then limit repeated failed logins, either with a security plugin or a web application firewall, and disable XML-RPC if nothing on your site uses it.
Finally, keep backups and check Search Console regularly so you hear about a problem early. Locking down logins and user roles is part of the WordPress SEO set-up and clean-up I do, because a hacked site undoes any search work very quickly.
