dictionary attack
A dictionary attack is a type of password-guessing technique that can be used to obtain unauthorized access to online accounts, databases, or computer systems. These attacks use a “dictionary,” or a list of likely passwords or other authentication information, to make repeated attempts to gain unauthorized access. The dictionary may consist of common words, phrases, numbers, previously compromised passwords, or information obtained from prior data breaches. Automated software can use these lists to make large numbers of login attempts in the hope that one of the entries will correspond to a valid password or credential.
Dictionary attacks are also used to send Unsolicited Commercial Email (UCE), commonly known as spam. Section 5(b) of the CAN-SPAM Act of 2003 addresses several techniques that Congress identified as particularly problematic and classifies them as aggravated violations. In its report on the legislation, the Senate Committee on Commerce, Science, and Transportation defined a “dictionary attack” as a practice in which a spammer sends messages to a succession of automatically generated email addresses, such as asmith@isp.com, bsmith@isp.com, and csmith@isp.com, in the expectation that some will correspond to real people. 15 U.S.C. § 7706 establishes the civil enforcement mechanisms and potential penalties for violations of the CAN-SPAM Act. The Federal Trade Commission (FTC) has general responsibility for enforcing the Act, although § 7706(b) assigns enforcement authority to additional federal agencies for specified entities. 15 U.S.C. § 7706(e) provides that, in certain FTC enforcement proceedings seeking a cease and desist order or an injunction, the Commission need not establish the offender’s state of mind. Section 7706(f) authorizes states to bring civil actions and permits them to seek monetary damages. For certain violations, damages may be calculated based on the number of violations, with each unlawful email constituting a separate violation, subject to statutory limits. Dictionary attacks constitute an aggravated violation under the Act, which permits a court to increase an otherwise available damages award by up to three times.
Dictionary attacks directed at obtaining passwords or other credentials may also implicate the Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. § 1030. The CFAA contains several distinct offenses, and not every offense requires the same elements. Several provisions prohibit intentionally or knowingly accessing a protected computer without authorization or exceeding authorized access. A dictionary attack may constitute one means of obtaining unauthorized access when the attacker uses repeated password-guessing attempts to gain access to a computer or account without permission.
The Second Circuit addressed password guessing in United States v. Morris, 928 F.2d 504 (2d Cir. 1991). This case involved a computer worm that utilized several methods to penetrate other computers, including a password-guessing program that tried various combinations of letters in rapid succession in an attempt to discover an authorized user’s password. In this case, the Second Circuit held that the evidence supported the jury’s finding that Morris had accessed computers “without authorization.” Although the Court in Morris interpreted an earlier version of the CFAA, the decision is significant because it recognized password guessing as a means to obtain unauthorized access to a computer.
The Fifth Circuit later applied Morris in United States v. Phillips, 477 F.3d 215 (5th Cir. 2007). In Phillips, a program was used to submit a list of Social Security numbers to a University of Texas computer system in an attempt to obtain access to information stored on the system. The Fifth Circuit cited Morris and concluded that the defendant’s conduct constituted unauthorized access under the CFAA. The Court explained that conduct such as password guessing can demonstrate unauthorized access when it is used to obtain access to a computer in a manner inconsistent with the computer owner’s intended use. Morris and Phillips both demonstrate that the CFAA can apply to automated password-guessing techniques when those techniques are used to obtain unauthorized access to protected computers; however, they do not establish that every single “dictionary attack” necessarily violates the CFAA. The applicability of the statute depends on the specific conduct and whether the elements of a particular CFAA offense are satisfied.
[Last reviewed in August of 2026 by the Wex Definitions Team]
Wex