Skip to main content

Unit 1 · Topic 1.2

1.2 Suspicious Website Logins

In an online password attack, someone tries likely passwords on a real login page until one works. This topic covers the warning signs of that attack, why passwords built from personal details are easy to guess, and how long unique passwords plus multifactor authentication protect your accounts.

Key terms

  • online password attack
  • password patterns
  • password manager
  • passphrase
  • multifactor authentication (MFA)

What an online password attack looks like

In an online password attack, the attacker types guesses into a live login page or device, usually with an automated tool that submits guesses much faster than a person. The guesses come from three places: very common passwords (like 123456 or password1), common password patterns, and real passwords stolen from other websites.

Because the attack happens on the real login system, it leaves tracks. Watch for these signs:

  • Many failed login attempts in a short time, like 40 wrong passwords in two minutes.
  • Login attempts at unusual times, like 3:12 a.m. for someone who only ever logs in after school.
  • Login attempts from unknown devices, often flagged by an email such as "New sign-in from an unrecognized device."

Why human-made passwords are easy to guess

People tend to build passwords the same few ways, and attackers know it. Common patterns include:

  • One or two words, then a two-digit number (often a year), then a special character at the end: Soccer24!, BlueTiger09#.
  • The name of a family member or pet: Biscuit2019.
  • A meaningful date like a birthday or anniversary: Maya0314.

How attackers build a custom guess list

An attacker who targets one person first gathers personal information about them, often from social media: pets' names, family names, birthdays, favorite teams, graduation year. They combine those pieces with the common patterns above to make a custom dictionary, which is a list of likely passwords. Then an automated tool submits the guesses one after another.

This is why a password like Rocky2009! feels strong (it has a capital letter, a number and a symbol) but isn't. If your dog Rocky appears in your posts and 2009 is your birth year, it's near the top of the attacker's list.

Making authentication stronger

  • Make passwords long, random and unique. Length matters most, and unique means every account gets its own password, so one stolen password can't open your other accounts.
  • Use a password manager, an app that generates strong random passwords and stores them for you, so you only remember one master password.
  • Or use a passphrase: several unrelated words strung together, like copper-violin-desert-pancake. It's long, so it's hard to guess, but easy for you to remember.
  • Avoid names, dates and other personally meaningful words or numbers.
  • Turn on multifactor authentication (MFA) wherever it's offered. MFA asks for extra proof, such as a one-time code from an app, on top of your password. Even if an attacker guesses your password, they still can't get in without that second proof.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Reading a login history

    A student checks the security page of her school email account and sees these entries: Mon 4:05 p.m., her laptop, success. Tue 2:51 a.m., unknown Windows device, failed. Tue 2:51 a.m., unknown Windows device, failed (this repeats 37 more times between 2:51 and 2:53 a.m.). Tue 3:40 p.m., her laptop, success. Identify the signs of an online password attack and recommend two actions.

    Show the solution
    1. Step 1: Look for many failures in a short time: 39 failed attempts in about two minutes is far more than a person mistyping.
    2. Step 2: Look at the time: 2:51 a.m. is unusual for this user, who normally logs in in the afternoon.
    3. Step 3: Look at the device: an unknown Windows device, not her laptop.
    4. Step 4: All three signs point to an automated online password attack. None of the attempts succeeded, so the account wasn't entered, but the attacker may try again.
    5. Step 5: Recommend actions that make the next attempt fail: change to a long, unique password (or passphrase), and turn on MFA so a correct guess alone isn't enough.

    Answer: Signs: 39 failed logins in about two minutes, at 2:51 a.m. (an unusual time), from an unknown device. Actions: switch to a long, unique password or passphrase, and enable multifactor authentication.

  2. Example 2

    Judging a password

    Jordan posts often about his cat, Pepper, and his birthday, May 12. He's choosing between Pepper0512! and lantern-orbit-maple-tulip. Which is stronger against an attacker who targets him, and why?

    Show the solution
    1. Step 1: Check Pepper0512! against the common patterns: a pet's name, then a meaningful date, then a special character. It fits the pattern exactly.
    2. Step 2: Check whether the pieces are public: Pepper and 05/12 both appear in Jordan's posts, so an attacker building a custom dictionary would include this combination early.
    3. Step 3: Check the passphrase: four unrelated words with no personal meaning, and 25 characters long. It isn't in any list built from Jordan's life.
    4. Step 4: Conclude based on guessability and length, not on whether it contains a symbol.

    Answer: lantern-orbit-maple-tulip is stronger. Pepper0512! follows a common pattern built from public personal details, so a targeted guess list would likely include it; the passphrase is long and unrelated to Jordan.

Common mistakes

  • Thinking a password is strong just because it has a capital letter, a number and a symbol. Soccer24! has all three and follows the most common pattern there is.
  • Mistaking one or two failed logins for an attack. The warning sign is many failures in a short time, or attempts at odd hours or from unknown devices.
  • Reusing one strong password everywhere. If any site that has it is breached, attackers try it on your other accounts, so each account needs its own.
  • Thinking MFA replaces a good password. It's an extra layer on top of the password, not a substitute for one.

On the exam

  • You may get a login history or a short scenario and be asked which detail signals a password attack. Point to the specific evidence: the number of failures and the time span, the unusual hour, or the unknown device.
  • For "how could this account be made more secure" questions, the strongest answers name a long, random, unique password (or a passphrase or password manager) and MFA.

Connected topics

Videos

  • AP Cybersecurity Topic 1.2 - Suspicious Website Logins. Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • Why You Should Turn On Two Factor Authentication

    Tom ScottWatch on YouTube (opens in a new tab)

  • Password Attacks - CompTIA Security+ SY0-701 - 2.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • AP Cybersecurity Topic 1.2: Password Attacks — Full Lesson Walkthrough

    AP CS Exam PrepWatch on YouTube (opens in a new tab)

  • How to Choose a Password - Computerphile

    ComputerphileWatch on YouTube (opens in a new tab)

  • Multi-factor Authentication - Cyber Safety Series

    CYBER. ORGWatch on YouTube (opens in a new tab)

Check yourself: 1.2 Suspicious Website Logins

5 questions on 1.2 Suspicious Website Logins. Pick an answer to see if you got it, and why.

Date and timeUsernameResultDevice
Sep 14, 2026 02:13:04jleeFailedUnknown device
Sep 14, 2026 02:13:06jleeFailedUnknown device
Sep 14, 2026 02:13:07jleeFailedUnknown device
Sep 14, 2026 02:13:09jleeFailedUnknown device
Sep 14, 2026 02:13:11jleeSuccessUnknown device
Sep 14, 2026 07:52:40jleeSuccessjlee-laptop (known)

Sign-in history for a student's account on an invented school portal

Question 1 of 5

Which of the following signs of an online password attack appear in the records?

Question 2 of 5

Which entry is the strongest evidence that the adversary now knows the student's password?

Question 3 of 5

Which security measure would most likely have stopped the adversary from getting into the account even after guessing the password?

Riley's public social media profile shows that Riley was born in 2009, plays soccer for the Hawks and has a dog named Pepper.

Riley is choosing a new password for a school account. Riley is considering four options: Pepper2009!, Hawks17#, P3pp3rHawks!, and a long random password created by a password manager.

Invented scenario

Question 4 of 5

An adversary builds a list of guesses from Riley's profile and runs it through an automated login tool. Which of Riley's options is most likely to be guessed first?

Question 5 of 5

Why is the password created by the password manager the best choice?

0 of 5 answered