An attack that tries a small number of commonly used passwords against a large number of accounts.
Because repeatedly guessing one account triggers a lockout, this attack instead tries a handful of simple passwords broadly across many accounts, trading depth for breadth to evade detection. Account lockout policies alone are not enough to stop it.
© 2026 ITBGM