What is an authentication attack?¶
An authentication attack tries to defeat, bypass or misuse the process a service uses to decide who is allowed access.
That is broader than password guessing.
It can target passwords, sessions, tokens, recovery, MFA, trusted devices, consent or single sign-on.
Different attacks target different parts of the access process¶
| Attack route | What it targets |
|---|---|
| Password spraying | Likely passwords across many accounts |
| Credential stuffing | Reused username/password pairs |
| Brute force | Many guesses against a target |
| Phishing | User disclosure or approval |
| MFA fatigue | Repeated prompts to obtain approval |
| Session/token theft | Existing authenticated access |
| Recovery abuse | Alternate route back into the account |
| Consent abuse | User grants a malicious application access |
That is why “authentication attack” should be the starting category, not the final technical description.
Ask what the service actually accepted¶
The relevant record may show:
- fresh password login;
- MFA approval;
- session refresh;
- token use;
- API action;
- trusted-device access;
- federated sign-in;
- recovery event.
No visible login does not mean no access¶
A stolen session or token may permit account use without a new password event.
Likewise, an already authenticated remote session can be misused.
Does a successful login prove the password was known? is the natural next question.
Authentication success is still not personal attribution¶
The service may correctly accept valid material used by an unauthorised person.
Shared accounts, automation and legitimate remote administration also need to be considered where they fit the facts.
The practical point is: identify which authentication mechanism was attacked and what the service accepted. Then follow the resulting session, device and account activity to establish what happened and who controlled it.