Your Password Isn't Being Brute-Forced: How Attackers Predict Human Behaviour
Learn how attackers exploit predictable behaviour, weak passwords and password reuse to compromise accounts more efficiently than brute force.
A modern cloud-based password cracking rig can generate around 20 billion NTLM hash candidates per second at relatively low cost.
That number sounds enormous, and it is. But it can also create the wrong impression about how password cracking actually works.
An attacker does not necessarily need to try every possible password. Modern password attacks combine huge amounts of computational power with something arguably even more useful: knowledge of how humans choose passwords.
The result is that password cracking is increasingly less about blindly grinding through every possible combination and more about predicting what a human is likely to have chosen.
What actually happens when a password is cracked?
When an attacker obtains a password hash, they generally aren't "decrypting" the hash to reveal the original password.
Instead, they generate password candidates, hash those candidates using the same algorithm and compare the resulting hashes with the stolen values.
For example:
Password
↓
NTLM hash function
↓
8846f7eaee8fb117ad06bdd830b7586c
During an offline cracking attack, the process works in the opposite direction:
Candidate password
↓
NTLM hash function
↓
Generated hash
↓
Compare with stolen hash
↓
Match = password recovered
The attacker does not need to reverse the mathematical operation. They simply need to find an input that produces the same hash.
This distinction becomes extremely important when the hashing algorithm is fast enough to allow enormous numbers of guesses per second.
Online guessing versus offline cracking
There is a major difference between trying passwords against a live service and testing password candidates against stolen hashes.
An online attack involves repeatedly attempting to authenticate to a service. The attacker may encounter:
- Rate limiting
- Account lockouts
- Multi-factor authentication
- Intrusion detection
- Network controls
- Security monitoring
An offline attack is different.
If an attacker obtains password hashes, they can potentially test password candidates without interacting with the authentication system at all.
That removes many of the controls that make online password guessing difficult.
This is where cracking speed becomes particularly important.
20 billion guesses per second changes the economics
Consider a cracking system capable of generating around 20 billion NTLM hash candidates every second.
That does not mean the attacker is generating 20 billion completely random passwords every second.
That would often be a waste of computational resources.
Instead, the attacker can generate candidates intelligently.
For example:
password
Password
Password1
Password1!
Password123
Password123!
Password2026
Password2026!
Each candidate can then be converted into an NTLM hash and compared against the stolen hash.
The important point is that computational power makes it cheap to test enormous numbers of candidates. But the selection and ordering of those candidates can make the attack dramatically more effective.
This is why password cracking isn't simply a contest between password length and processor speed.
It is also a prediction problem.
The attacker doesn't need to try every password
Imagine that a password consists of six completely random characters.
The theoretical search space is enormous compared with a password selected from a relatively small collection of familiar words and patterns.
Humans don't generally choose passwords randomly.
We choose things that are meaningful to us.
Common examples include:
- Names
- Football teams
- Children's names
- Pets
- Companies
- Places
- Favourite bands
- Birth years
- Dates
- Seasons
- Current years
- Familiar words
- Keyboard patterns
We then modify those choices when a website imposes password requirements.
A password might start as:
Liverpool
A complexity requirement might turn it into:
Liverpool1
And then:
Liverpool1!
The password now appears considerably more complex.
From an attacker's perspective, however, the underlying choice may still be highly predictable.
The attacker doesn't need to search the entire theoretical password space. They can prioritise combinations that people are statistically more likely to have chosen.
Humans create predictable password patterns
This is one of the fundamental problems with passwords.
Suppose somebody chooses:
Liverpool
A password policy requires a number:
Liverpool1
The policy then requires a special character:
Liverpool1!
When the organisation requires a password change, the user might choose:
Liverpool2!
Or perhaps:
Liverpool2026!
The password has changed, but the underlying behaviour hasn't.
An attacker who understands these patterns can generate candidates that reflect how people actually modify passwords.
This is why adding a number and a special character does not necessarily provide the security improvement that a password policy might suggest.
Complexity rules don't always solve the problem
For years, many organisations have used rules such as:
Your password must contain uppercase and lowercase characters, a number and a special character.
There is nothing inherently wrong with requiring passwords to meet certain technical criteria in some circumstances. The problem is assuming that those rules automatically produce unpredictable passwords.
Humans adapt to requirements.
Consider:
Password
Password1
Password1!
Password1!2026
Every version can satisfy increasingly complicated password rules while retaining the same underlying structure.
The more predictable the transformation, the easier it is for an attacker to model.
Modern password guidance has therefore moved away from relying solely on arbitrary composition rules and towards measures such as longer passwords, screening against compromised passwords and preventing the use of common or predictable credentials.
The important distinction is between a password that merely satisfies a complexity policy and one that is genuinely difficult to predict.
Attackers can use what they already know about you
Password attacks don't necessarily operate in a vacuum.
Suppose an attacker is targeting an organisation called:
Plainsight Security
They might prioritise candidates containing words associated with the organisation:
Plainsight
Security
PlainsightSecurity
Plainsight2026
Security2026
Plainsight123
Plainsight!
The same principle applies to individual users.
Information that may be publicly available or otherwise known could include:
- Username
- Employer
- Location
- Sports team
- Hobbies
- Favourite bands
- Names
- Previous passwords
- Previously compromised credentials
This is context-aware password guessing.
The attacker is effectively reducing the search space by making educated assumptions about what the target is likely to have chosen.
That can be considerably more efficient than blindly generating random combinations.
Previous passwords are incredibly valuable
Password reuse creates another significant problem.
Suppose an attacker discovers that a user's previous password was:
Summer2024!
They don't necessarily assume that the password is still being used.
They may instead consider predictable variations:
Summer2025!
Summer2026!
Summer2026
Summer2026!!
Summer2024
The exact variations will depend on the attacker's techniques and available information, but the principle is simple:
A known password can provide information about how somebody chooses passwords.
This is one reason password reuse is particularly dangerous.
A password that hasn't appeared in a particular breach does not automatically mean it is unpredictable.
Password length still matters
None of this means that password length is unimportant.
Quite the opposite.
A long, randomly generated password is fundamentally different from a long password constructed from predictable human choices.
Compare:
LiverpoolFootballClub2026!with a genuinely random password generated by a password manager.
Both may be long. But length alone doesn't make the first password unpredictable.
A password containing familiar words, personal information and predictable substitutions may be much easier for an attacker to prioritise than its apparent complexity suggests.
Three random words
For users who need to create and remember their own passwords, the UK's National Cyber Security Centre (NCSC) recommends using three random words.
For example:
tiger-window-coffeeThe important word here is random.
Choosing three words that have a personal connection, such as:
Liverpool-Football-Anfieldis not equivalent. Those words are connected and therefore potentially predictable to someone who knows something about the user.
Three genuinely random words provide a useful balance between length, memorability and resistance to guessing. Adding predictable substitutions or information such as a birth year or the current year does not necessarily make the password significantly stronger.
For higher-value accounts, a password manager can go further by generating long, unique and randomly generated passwords that don't need to be remembered at all.
The goal should therefore be length and unpredictability, not simply satisfying a checklist of character types.
What businesses should actually do
For businesses, protecting against password attacks requires more than telling employees to invent complicated passwords.
Use multi-factor authentication
MFA adds another layer of protection if a password is compromised.
A stolen password should not automatically provide an attacker with everything they need to authenticate.
Use password managers
Password managers can generate long, unique passwords without requiring users to invent and remember them.
That changes the problem fundamentally.
Instead of asking a human to create another password that they will remember, the system can generate a credential that is genuinely difficult to predict.
Block known compromised passwords
Organisations should prevent users from choosing passwords that are:
- Known to have been compromised
- Extremely common
- Based on obvious organisational information
- Based on usernames
- Easily derived from other known information
A password can be technically complex and still be a poor password if thousands of other people have already used it.
Don't rely on forced periodic password changes
Forcing users to change passwords every 30, 60 or 90 days can encourage predictable mutations.
A user who is forced to change:
Summer2025!
might simply choose:
Summer2026!
Changing a password because there is evidence of compromise is very different from changing it purely because a calendar says it is time to do so.
Protect password hashes
The security of a password also depends on how the system stores and verifies it.
Modern applications should use appropriately configured, salted password hashing algorithms designed to make offline password guessing computationally expensive.
This is an important distinction from systems using fast hashing mechanisms such as NTLM.
The same password can therefore present very different risks depending on how its associated credential data is protected.
Why NTLM matters in Active Directory environments
For organisations using on-premises or hybrid Windows environments, NTLM deserves particular attention.
NTLM is part of Microsoft's authentication ecosystem and remains relevant in many Active Directory environments.
The security problem isn't simply the existence of NTLM. The bigger issue is what happens if an attacker obtains useful credential material and can subsequently perform offline password guessing or use those credentials in further attacks.
This is particularly significant for:
- Domain accounts
- Privileged accounts
- Service accounts
- Local administrator accounts
- Accounts with excessive privileges
- Accounts using reused passwords
A weak domain password isn't necessarily just a compromised user account.
Depending on the wider environment and the privileges associated with that account, it can potentially become a starting point for privilege escalation, lateral movement and ultimately domain compromise.
This is why password security should be considered part of the wider Active Directory security model rather than treated as an isolated user-awareness issue.
What password auditing actually tests
Password auditing during an authorised penetration test is not simply a question of counting characters.
Depending on the engagement and agreed scope, testers may assess whether passwords can be recovered using approaches such as:
- Dictionary attacks
- Rule-based attacks
- Mask attacks
- Password mutation
- Previously compromised passwords
- Organisation-specific candidate generation
The purpose isn't to demonstrate that a sufficiently powerful computer can eventually guess a password.
The purpose is to determine whether the organisation's passwords are resistant to realistic attack techniques.
That distinction matters.
A password that would theoretically take an enormous amount of time to brute-force randomly might still be recovered quickly if it follows a highly predictable pattern.
The real problem with passwords
The problem with passwords isn't simply that computers are getting faster.
It's that humans are predictable.
Modern password cracking combines enormous computational power with knowledge of how people actually choose passwords.
An attacker doesn't necessarily need to search every possible password. They can prioritise the passwords humans are most likely to have chosen.
For businesses, the answer isn't simply to demand increasingly complicated passwords.
A stronger approach combines:
- Long, unique passwords
- Password managers
- MFA
- Compromised-password protection
- Appropriate controls around privileged accounts
- Secure password storage
- Regular security testing
The most important lesson is simple:
Password security isn't about making passwords complicated enough to frustrate humans. It's about making credentials unpredictable enough to frustrate attackers.
Put this into practice.
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.