How Do Hackers Steal Passwords? 5 Attack Methods Explained

1.7M views
•
April 24, 2025
by
IBM Technology
YouTube video player
How Do Hackers Steal Passwords? 5 Attack Methods Explained

TL;DR

Hackers steal or discover passwords through five methods: guessing, harvesting, cracking, password spraying, and credential stuffing. Defenses include long, unique passwords stored in a password manager, multi-factor authentication, passkeys, rate limiting, and checks against databases of known vulnerable passwords. Read on to understand how each attack works and why different safeguards are needed.

Transcript

Have you ever wondered how a bad guy hacks your password? It's a big problem. In fact, according to both IBM's Cost of a Data Breach Report and the X-Force Threat Intelligence Index, stolen, misused, or otherwise compromised credentials are the number one attack type. There are lots of ways this is done, but in this video, I'm gonna focus on five d... Read More

Key Insights

  • Password guessing is an attempt to predict a credential using imagination, knowledge about an individual, passwords exposed on nearby notes, or databases created from previous breaches. Account lockout policies commonly limit this approach by stopping further attempts after three incorrect guesses.
  • Password harvesting is the direct collection of a valid credential through malware or deception. A keylogger or information stealer can record typed passwords, while a phishing site can imitate a legitimate login page and send the submitted credentials to an attacker.
  • Password cracking works by hashing candidate passwords and comparing the results with hashes extracted from a stolen password database. The attacker does not reverse the one-way hashing process, but identifies a password when a newly calculated hash matches a stored one.
  • Password dictionaries and publicly known password lists make cracking more targeted than testing arbitrary combinations. If those sources fail, an attacker can attempt brute force by trying every possible password combination and hashing each candidate for comparison with the stolen hashes.
  • Password spraying applies one likely password across many accounts within a single system. Because each account receives only one attempt before the attacker moves to the next, the attack can avoid three-strike lockouts and remain difficult to notice when conducted slowly.
  • Credential stuffing applies a password across multiple systems rather than multiple accounts in one system. It exploits password reuse and can be harder to detect because separate systems may be monitored by different security personnel who cannot see the complete pattern.
  • Password length is a major source of password strength, and excessive complexity can encourage people to write credentials down. Systems should also reject passwords found in databases of known vulnerable credentials and, when possible, identify reuse across multiple systems.
  • Passkeys replace passwords with a stronger solution based on cryptographic techniques. Other recommended protections include password managers, multi-factor authentication, and rate limiting that rejects abnormal bursts of login attempts after normal authentication traffic has been baselined.

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What are the five main methods hackers use to steal passwords?

The five methods are password guessing, harvesting, cracking, password spraying, and credential stuffing. Guessing predicts credentials, harvesting captures them, and cracking matches candidate-password hashes against stolen hashes. Spraying tests one password across many accounts in one system, while stuffing tries a password across multiple systems.

Q: How does password guessing work?

An attacker chooses a possible password using imagination, knowledge about the account owner, a password seen on a nearby note, or credentials exposed in an earlier breach. The attacker then attempts to log in, but many systems lock the account after three incorrect guesses. This makes ordinary guessing ineffective unless the attacker makes an informed guess quickly.

Q: How do keyloggers and phishing sites harvest passwords?

A keylogger or information stealer records what someone types, including passwords, and stores the data or sends it to the attacker in real time. A phishing site instead imitates a legitimate website and collects credentials entered by the victim. Both methods give the attacker the actual password rather than requiring a guess.

Q: How does password cracking reveal a hashed password?

The attacker takes password hashes from a stolen database and hashes readable candidates using the same method. Candidates may come from publicly known password lists, password dictionaries, or brute-force attempts covering every possible combination. A matching hash reveals which candidate produced the stored hash without reversing the one-way hashing process.

Q: What is the difference between password spraying and credential stuffing?

Password spraying applies one likely password to many accounts within a single system. Credential stuffing applies a password across multiple systems, exploiting password reuse. Stuffing can be harder to detect because separate systems may be monitored by different security personnel who cannot see the complete pattern.

Q: Why can password spraying avoid account lockouts?

Password spraying distributes attempts across many accounts instead of repeatedly targeting one account. The attacker tries the selected password once per account before moving to the next. Because each account receives fewer failures, a three-strike lockout policy may not activate, especially when the attempts occur slowly.

Q: How can people create and manage safer passwords?

People should use long passwords, reject credentials found in databases of known vulnerable passwords, and avoid reusing a password across systems. A password manager can generate strong credentials and keep track of them. This reduces the pressure to memorize every password or write credentials down.

Q: What security controls help stop password attacks?

Recommended controls include password managers, multi-factor authentication, passkeys, rate limiting, and monitoring for repeated authentication failures over time. Systems should encourage long, unique passwords and check proposed credentials against known vulnerable-password databases. Rate limiting can reject abnormal bursts of login attempts after normal authentication traffic has been baselined.

Summary & Key Takeaways

  • Password guessing uses personal knowledge, exposed notes, imagination, or passwords revealed in previous breaches to predict a credential. Because many systems lock an account after three failed attempts, ordinary guessing is unlikely to succeed unless the attacker makes an informed guess that proves correct within the permitted attempts.

  • Harvesting captures credentials directly instead of predicting them. Keyloggers and information-stealing malware can record everything typed and send or store the data for an attacker. Phishing achieves a similar result by directing a person to a fake website where entered credentials flow directly to the attacker.

  • Cracking compares hashes of candidate passwords with stolen password hashes, while spraying and stuffing reuse likely passwords across accounts or systems. Recommended defenses include long unique passwords, password managers, multi-factor authentication, passkeys, rate limiting, checks against known vulnerable passwords, and detection of repeated authentication failures over time.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from IBM Technology 📚