The chain, step by step
Each step depends on the one before it. Break any link and the chain stops there.
-
1
Step 1 of 8
A breach dump from an unrelated service is obtained, containing hundreds of millions of pairs.
-
2
Step 2 of 8
Known-invalid entries are filtered out so only plausible credentials remain.
-
3
Step 3 of 8
Those pairs are sprayed against the target login endpoint at low volume to evade rate limits.
-
4
Step 4 of 8
Distributed source infrastructure keeps any single IP below alert thresholds.
-
5
Step 5 of 8
Successful logins are identified by comparing response shape against genuine failures.
-
6
Step 6 of 8
Matched accounts are tested for whether the same password guards other services.
-
7
Step 7 of 8
High-value accounts with payment methods or administrative rights are prioritised.
-
8
Step 8 of 8
Access is monetised through fraud, resale or further escalation inside the organisation.
Entries behind these steps
The vulnerabilities, techniques and malware that make each stage possible.