Azure

An AI Bot Is Attacking Your Login

8,000 password attempts a minute, while nobody's watching.

What you'll learn

  • Why an automated attacker changes the maths, not just the volume
  • Why watching your logs is not a defence against something that never sleeps
  • The three Azure controls that make speed useless: rate limits, lockout, alerts
Azure Security 8 steps 25 seconds views

Was this useful?

Share

Understand it one step at a time

The short runs these in order in about 25 seconds. Here they are written out — pick any step to jump the short straight to it.

1 Step 1 of 8

Nobody is typing

It’s three in the morning and nobody is at a keyboard — a script is running this because that’s exactly when nobody’s watching.

Frequently asked questions

Why doesn't watching your logs defend against an automated attacker?
An automated attacker doesn't sleep, and volume is the whole point — it changes the maths, not just the scale, so a human reviewing logs after the fact is always behind. The defence has to be automatic too.
What actually stops a credential-stuffing bot?
Three controls at the API itself, not the UI: rate limiting takes away its speed, smart lockout plus MFA makes a correct guess useless, and a service like Defender for Cloud watches continuously. A CAPTCHA on a web form does nothing if the bot is calling the API directly.

Free app · no app store

These are built for a phone

Every short is drawn at full portrait height, the shape a phone already is. Installed, it opens full-bleed with no address bar across the top — and the whole library reads offline.

How it works

Read deeper on Azure

Twenty seconds gets the shape of an idea across. These go into how it behaves in production.

More shorts

Get new posts by email

New technical articles, Azure AI and GitHub Copilot updates, and upcoming events. No spam, unsubscribe anytime.

navigate open