A brute force attack uses automated attempts to guess an account password by trying many possible combinations.
Why are email accounts targeted?
Access to a mailbox may expose business conversations, password-reset messages and the ability to send email using a trusted employee identity.
How can the attack be detected?
A large number of failed login attempts against the same username in a short period can be a strong signal. Attempts may originate from one address or from many distributed sources.
Why strong passwords matter
Short or predictable passwords are more vulnerable to automated guessing. Strong and unique credentials reduce the probability of success.
Automated blocking
Temporarily or permanently blocking sources after repeated failures can reduce continuous password attempts.
Monitor login activity
Blocking alone is not enough. Understanding which accounts are targeted and how frequently attacks occur provides useful operational security visibility.
For password guidance, read How to Create a Strong Password for Business Email.