How Password Cracking Scripts Work and How to Stop Them
Published February 13, 2024, updated August 4, 2026
A password cracking script is an automated program that guesses passwords at machine speed, either by trying them against a login page directly or by working through a stolen copy of a password database. The two defenses that reliably hold up against them are multi-factor authentication and long, unique passwords kept in a password manager. This post explains how the attacks actually work, in plain English, and what an owner or office administrator at a small practice can change this month without a security background.
What a password cracking script actually does
There are two settings where these tools run, and they behave differently.
The first is online guessing: the script points at a real login page, such as your Microsoft 365 sign-in, and submits guesses. This is slow by cracking standards, because the service can throttle or lock accounts after repeated failures, so attackers here favor a small number of likely passwords over an exhaustive search.
The second is offline cracking. Systems do not store your password as you typed it; they store a scrambled version of it called a hash. If attackers steal a copy of a password database, from your systems or from some unrelated website you have an account on, they can test guesses against those hashes on their own hardware with nothing to slow them down. Modern cracking rigs test enormous numbers of guesses per second, which is why a short password that feels fine at the keyboard can fall quickly once the guessing moves offline.
The four techniques, in plain English
Brute force tries every possible combination of characters in order. Its only enemy is length. Each character you add multiplies the work, which is why the practical advice further down is about longer passwords rather than more exotic ones.
Dictionary attacks skip the exhaustive search and work through lists instead: common passwords, words, names, dates, and every password that has ever appeared in a public breach, plus the predictable variations. Swapping letters for symbols does not help much here, because "P@ssw0rd1" is already on the list.
Credential stuffing does not guess at all. Attackers take email and password pairs leaked from one website's breach and try them everywhere else, betting that people reuse passwords across accounts. When a staff member's personal shopping login matches their work login, this is the technique that connects the two.
Password spraying flips the pattern: instead of many guesses against one account, it tries one likely password, something like a season plus the year, against many accounts, slowly, to stay under lockout thresholds. This is the traffic that Microsoft 365 tenants see in their sign-in logs more or less continuously.
Why a small practice sees this at all
None of this is personal. The scripts do not know or care that you are a six-chair dental office in Gilbert or a two-partner law firm in Chandler; they work through lists of email addresses and login pages automatically, and every Microsoft 365 tenant has a sign-in page reachable from anywhere. Being small does not take you off the list, because nobody is maintaining a list.
What raises the stakes for a practice is what sits behind the password. Patient records, case files, and financial data carry notification obligations under HIPAA and similar rules when an account holding them is compromised, so the cost of a cracked password is not just the cleanup, it is the reporting that can follow. That side of the picture belongs to your compliance posture as much as your technical one.
What actually stops it
Multi-factor authentication first
Multi-factor authentication, often shortened to MFA, means the account asks for a second proof of identity beyond the password, usually a prompt or code on your phone. It breaks the economics of every technique above, because a correct guess no longer opens anything on its own. Microsoft's analysis of attacks on its own identity platform found that multi-factor authentication blocks over 99.9 percent of account compromise attempts. It is included in every Microsoft 365 business plan, and most cyber insurance applications now ask directly whether it is turned on. If you make one change after reading this, this is the one.
Length beats complexity
The current guidance from NIST, the US standards body, in Special Publication 800-63B treats length as the primary defense against guessing attacks and moves away from forced symbol-and-number composition rules. A passphrase of four or five random words is both stronger against a cracking rig and easier for a human to type than eight characters of line noise.
The same guidance dropped the old requirement to change passwords every 60 or 90 days, because forced rotation pushes people toward predictable patterns like incrementing a number at the end. Change a password when there is a reason to, such as a suspected compromise, and otherwise let a strong one stand.
The practical way to get length and uniqueness at the same time is a password manager, a vault application that generates and remembers a different strong password for every account. It is the direct answer to credential stuffing, because a breach at some unrelated website no longer hands anyone a working key to your systems.
Let the platform do its part
Microsoft 365 already includes protections aimed at exactly these scripts. Smart lockout slows online guessing by locking out attackers after repeated failures while recognizing the legitimate user, and Microsoft Entra password protection screens new passwords against a global list of known weak choices. These features do their job quietly, but they are worth confirming rather than assuming, and the sign-in logs they feed are only useful if someone actually reads them. Spotting the pattern of a spray campaign, or a successful login from somewhere no employee has ever been, is monitoring work, and it is a core part of what a managed security service watches for.
Rolling this out without breaking the front desk on a Monday morning, the password manager choice, the MFA enrollment sequence, the sign-in policies, is a modest project, and the sort of thing day-to-day IT management handles as routine.
Frequently asked questions
What is a password cracking script?
A password cracking script is an automated program that guesses passwords at high speed. Some run against a login page directly, trying common passwords across many accounts. Others run offline against a stolen copy of a password database, testing enormous numbers of guesses per second against the scrambled entries.
Does multi-factor authentication stop password cracking?
It stops the part that matters. A cracked password alone does not open an account that asks for a second proof of identity. Microsoft's analysis of attacks on its own identity platform found that multi-factor authentication blocks over 99.9 percent of account compromise attempts, which is why it is the first change worth making.
How long should a password be?
Longer is what matters. NIST, the US standards body, recommends allowing long passphrases and treats length as the primary defense against guessing attacks, ahead of special-character rules. A passphrase of four or five random words holds up far better than a short password with symbols swapped in, and it is easier to remember.
What is credential stuffing?
Credential stuffing is when attackers take email and password pairs leaked from one website's breach and try them on other services, betting that people reuse passwords. It works often enough to be a standard technique, and it is the reason a unique password per account matters as much as a strong one.
How often should we change passwords?
Only when there is a reason to, such as a suspected breach. NIST dropped the old advice of forced changes every 60 or 90 days because it pushes people toward predictable patterns like incrementing a number. A long unique password with multi-factor authentication behind it can stay put.
Getting ahead of password cracking scripts
Password cracking scripts are automated, constant, and indifferent to the size of your business, which sounds grim until you notice that the defenses are cheap and mostly already included in what you pay for. Multi-factor authentication, a password manager, and someone watching the sign-in logs close off the overwhelming majority of it.
If you would like to know which of those pieces are actually in place in your practice today, Desert Lakes Solutions offers a no-pressure discovery call to walk through your current setup and point out the easy wins. Book a discovery call.