Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is an authentication attack?

An authentication attack tries to defeat, bypass or misuse the process a service uses to decide who is allowed access.

That is broader than password guessing.

It can target passwords, sessions, tokens, recovery, MFA, trusted devices, consent or single sign-on.

Different attacks target different parts of the access process

Attack route What it targets
Password spraying Likely passwords across many accounts
Credential stuffing Reused username/password pairs
Brute force Many guesses against a target
Phishing User disclosure or approval
MFA fatigue Repeated prompts to obtain approval
Session/token theft Existing authenticated access
Recovery abuse Alternate route back into the account
Consent abuse User grants a malicious application access

That is why “authentication attack” should be the starting category, not the final technical description.

Ask what the service actually accepted

The relevant record may show:

  • fresh password login;
  • MFA approval;
  • session refresh;
  • token use;
  • API action;
  • trusted-device access;
  • federated sign-in;
  • recovery event.
Attack routeHow was access challenged or bypassed?Guessing, reuse, phish, token or recovery.
AuthenticationWhat did the service accept?Password, factor, token, trusted device or other method.
SessionWhat access followed?Account activity and attribution come next.

No visible login does not mean no access

A stolen session or token may permit account use without a new password event.

Likewise, an already authenticated remote session can be misused.

Does a successful login prove the password was known? is the natural next question.

Authentication success is still not personal attribution

The service may correctly accept valid material used by an unauthorised person.

Shared accounts, automation and legitimate remote administration also need to be considered where they fit the facts.

The practical point is: identify which authentication mechanism was attacked and what the service accepted. Then follow the resulting session, device and account activity to establish what happened and who controlled it.

Reference: CIM-050Cyber Incidents & Offender Methods