How Do Cybercriminals Get My Password?

How do cybercriminals get hold of my password? In this blog series, you'll learn all about different types of cybercrime.

Passwords form the first line of defense against unauthorized access to personal and business accounts. Yet cybercriminals manage to break through these barriers using certain attack methods. In this blog, we explain how cybercriminals can crack your password.

Buying passwords online / dark web

One of the most alarming ways cybercriminals obtain passwords is by simply buying them online, often via the dark web or via Telegram. After large companies fall victim to data breaches, stolen passwords end up in enormous databases that are traded online. This data is often combined with usernames or email addresses, making it easy for criminals to gain access to victims' other accounts. The price of these lists varies depending on their quality and exclusivity, but even for a few euros, a hacker can already get their hands on an extensive set.

Brute Force Attack

The brute force attack is a more large-scale approach in which all possible character combinations are tried. This method requires considerably more computing power and time, since the process is not based on a list of known passwords but purely on the computing capacity of automated systems. The strength of this attack lies in its certainty: if no restrictions are in place, every password will eventually be cracked.

Dictionary Attack

A dictionary attack is a systematic attack method in which a list of common passwords or meaningful words is used to gain access to an account. This list, also known as a 'dictionary', contains combinations based on commonly used passwords or language patterns. Cybercriminals rely on the predictability of human choices to achieve maximum results with minimal effort.

Reverse Brute Force Attack

In a reverse brute force attack, the order is reversed. Instead of testing random accounts with different passwords, one specific password is tried against a large number of accounts. This approach is particularly effective in scenarios where a leaked password is known, but the corresponding user data cannot be directly linked to it.

Multi-factor authentication as extra security

Multi-factor authentication (MFA) is an important step in protecting your online accounts against unauthorized access. Traditional security often relies on only one factor, such as a password. Unfortunately, passwords are vulnerable; they can not only be cracked using the methods above, but also stolen through phishing.

With MFA, you add a second (or even a third) layer of security. This could, for example, be a one-time code sent to your phone, a biometric verification such as a fingerprint/facial recognition, or a physical security key. This makes it considerably harder for attackers to gain access to your account, even if they have your password.

How do I improve my password policy?

If you want to learn more about improving your passwords, we recommend reading our blog on ''what is a good password policy?''. Now that you understand the potential risks of a poor password policy, you can start thinking about implementing improvements.

Related articles