{"id":18648,"date":"2026-03-03T09:41:15","date_gmt":"2026-03-03T09:41:15","guid":{"rendered":"https:\/\/www.20i.com\/blog\/?p=18648"},"modified":"2026-03-05T10:47:46","modified_gmt":"2026-03-05T10:47:46","slug":"how-strong-passwords-and-mfa-secure-your-hosting-account","status":"publish","type":"post","link":"https:\/\/www.20i.com\/blog\/how-strong-passwords-and-mfa-secure-your-hosting-account\/","title":{"rendered":"How Strong Passwords and\u00a0MFA Secure Your Hosting Account\u00a0"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In the&nbsp;<a href=\"https:\/\/www.20i.com\/web-hosting\" data-internallinksmanager029f6b8e52c=\"16\" title=\"web hosting\">web hosting<\/a>&nbsp;industry, security breaches rarely start with someone&nbsp;\u201chacking\u201d their way&nbsp;into&nbsp;the servers.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Far more often, they begin with&nbsp;attacks on the&nbsp;individual, by&nbsp;stealing&nbsp;login&nbsp;credentials or&nbsp;brute force&nbsp;entry.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whether&nbsp;you\u2019re&nbsp;a website owner managing a single site or a reseller responsible for&nbsp;your&nbsp;customer\u2019s&nbsp;accounts, your hosting credentials are one of the most valuable targets an attacker can find.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this post, we will explore different password-based attacks, how they work, common targets and how to keep your accounts safe.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Why Hosting Accounts Are a High-Value Target<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Most attacks are automated by bots, continuously scanning the internet for weak credentials or purchasing leaked credentials sold on the dark web.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These types of attacks are indiscriminate; being a small site or a small business does not reduce the&nbsp;risk.&nbsp;A&nbsp;single hosting account can provide access to:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Website files and databases&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Client information&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Email accounts&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>DNS and domain settings&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Backups&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Other customer accounts (in the case of resellers)&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For attackers, compromising one login can mean&nbsp;full control&nbsp;of a website&nbsp;or an entire reseller environment.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers&nbsp;don\u2019t&nbsp;need to \u201cbreak in\u201d if they can simply log in&nbsp;using your credentials.&nbsp;Common targets include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hosting control panels&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>WordPress admin logins&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>FTP\/SFTP accounts&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub accounts&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Email accounts tied to the domain&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Once access is gained, attackers can&nbsp;steal information,&nbsp;upload malware, redirect traffic, send spam,&nbsp;pivot to other accounts&nbsp;and change personal information to complicate the process of recovering your account.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Common Password Attacks Seen in Hosting Environments<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Password attacks&nbsp;comprise&nbsp;a range of techniques that aim to obtain valid credentials rather than exploit software vulnerabilities.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In hosting environments, these attacks are&nbsp;largely automated&nbsp;and target exposed authentication points such as control panels, CMS logins, and email services.&nbsp;&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Brute-Force Attacks<\/strong>&nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Automated systems attempt thousands of password combinations in a short time. Short or simple passwords are quickly cracked, especially where login attempts are not restricted.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many website owners will implement&nbsp;preventative measures such as enforcing&nbsp;CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart)&nbsp;or limiting login attempts.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On our secure hosting platform&nbsp;at 20i, brute force prevention is included, configured,&nbsp;and enabled automatically&nbsp;as part of&nbsp;<a href=\"https:\/\/www.20i.com\/blog\/protecting-password\/\" target=\"_blank\" rel=\"noreferrer noopener\">StackProtect<\/a>&nbsp;security suite.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Dictionary Attacks<\/strong>&nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of random guesses, attackers use lists of&nbsp;<a href=\"https:\/\/www.passwordmanager.com\/most-common-passwords-latest-statistics\/\" target=\"_blank\" rel=\"noreferrer noopener\">common passwords<\/a>&nbsp;and predictable patterns such as&nbsp;Spring2025!&nbsp;or&nbsp;CompanyName123.&nbsp;This can be surprisingly effective, even in 2026.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Credential Stuffing<\/strong>&nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This is one of the most effective attack&nbsp;methods.&nbsp;Attackers use email\/password combinations leaked from&nbsp;<a href=\"https:\/\/www.bbc.co.uk\/news\/business-41493494\" target=\"_blank\" rel=\"noreferrer noopener\">unrelated data breaches<\/a>&nbsp;and try them against hosting services, relying on&nbsp;credential&nbsp;reuse.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Rainbow Table Attacks<\/strong>&nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Most&nbsp;passwords are stored in a hashed&nbsp;format, usually with the MD5&nbsp;(Message Digest 5) and SHA1 (Secure Hashing Algorithm 1)&nbsp;cryptographic hashing function.&nbsp;When in this hashed state, the passwords are unreadable and therefore unusable.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where weak hashing or short passwords are involved, precomputed tables, known as rainbow tables,&nbsp;can be used to rapidly&nbsp;<em>\u2018reverse\u2019<\/em>&nbsp;stolen password hashes.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While impossible to&nbsp;<em>\u2018reverse\u2019<\/em>&nbsp;a password hash, attackers will have a table of known passwords and associated hash values.&nbsp;Tools will match the stolen password hash to a known password hash in the table.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How Strong, Unique&nbsp;Passwords Reduce Risk<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Strong passwords significantly slow down and often completely stop automated attacks&nbsp;due to the time and computational power investment required.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Best practices include:&nbsp;<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Using&nbsp;long passwords&nbsp;(length matters more than complexity)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Never reusing passwords across services&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Using a password manager to generate and store unique credentials&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Avoiding predictable patterns or minor&nbsp;mutations&nbsp;of old passwords&nbsp;(e.g. Password123 to Password 1234!)&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For resellers, this is especially important. One weak master password can expose multiple customer environments.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.nist.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">NIST<\/a>&nbsp;(National Institute of Standards and Technology) recommends&nbsp;aiming&nbsp;for 16 characters with a mixture of uppercase &amp; lowercase letters,&nbsp;numbers&nbsp;and special characters.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1201\" height=\"1107\" src=\"https:\/\/www.20i.com\/blog\/wp-content\/uploads\/2026\/02\/strong-pw-mfa-inner-1.png\" alt=\"NIST Recommended password strength chart\" class=\"wp-image-18649\" srcset=\"https:\/\/www.20i.com\/blog\/wp-content\/uploads\/2026\/02\/strong-pw-mfa-inner-1.png 1201w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-1-300x277.png.webp 300w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-1-768x708.png.webp 768w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-1-400x369.png.webp 400w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-1-800x737.png.webp 800w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-1-832x767.png.webp 832w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-1-150x138.png.webp 150w\" sizes=\"auto, (max-width: 1201px) 100vw, 1201px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why Passwords Alone Are No Longer Enough<\/strong>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many people reuse the same passwords or mutated versions&nbsp;of their main password across different services.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an illicit actor comes to&nbsp;possess&nbsp;your credentials for a specific website, they will then&nbsp;try&nbsp;the same credentials across multiple other services, such as banking&nbsp;applications.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If using the same credentials, a single account breach can evolve into multiple accounts being compromised, increasing potential damage and making it more difficult to recover accounts&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even long, complex passwords can be&nbsp;reused across services, stolen via&nbsp;<a href=\"https:\/\/docs.20i.com\/my-services\/how-can-i-identify-a-20i-phishing-email\" target=\"_blank\" rel=\"noreferrer noopener\">phishing<\/a>&nbsp;and exposed through third-party breaches.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once an attacker has the correct password, there is nothing stopping them from logging in&nbsp;and causing damage&nbsp;unless another layer of protection exists.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How&nbsp;MFA&nbsp;Stop Attacks<\/strong>&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Multi&nbsp;factor authentication&nbsp;adds&nbsp;additional&nbsp;requirements&nbsp;beyond the password&nbsp;that&nbsp;can be&nbsp;categorised&nbsp;as:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Something you know \u2013 a password or PIN&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Something you have \u2013 a phone, hardware token, or authenticator app&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Something you are \u2013 biometrics like a fingerprint or facial recognition&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This means:&nbsp;<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Stolen or reused passwords are no longer enough&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Automated attacks fail at the second step&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Phished credentials cannot be used without physical access to the device&nbsp;or biometric data&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Many 2FA apps also allow you to lock access to the app behind a pin, facial&nbsp;recognition&nbsp;or fingerprint, adding further security to your accounts in the chain.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At 20i, we allow the use of&nbsp;Google,&nbsp;Microsoft,&nbsp;Authy,&nbsp;AuthenticatorCC,&nbsp;Ente,&nbsp;2fast,&nbsp;2stable Authenticator,&nbsp;Raivo&nbsp;and more.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If&nbsp;you&#8217;d&nbsp;prefer a different app, our 2FA system&nbsp;is&nbsp;compatible with all standard&nbsp;TOTP&nbsp;(Time-based One-Time Passcode)&nbsp;apps.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1201\" height=\"802\" src=\"https:\/\/www.20i.com\/blog\/wp-content\/uploads\/2026\/02\/strong-pw-mfa-inner-2.png\" alt=\"Time-Based One-Time Passcode Apps (TOTP) image.\" class=\"wp-image-18650\" srcset=\"https:\/\/www.20i.com\/blog\/wp-content\/uploads\/2026\/02\/strong-pw-mfa-inner-2.png 1201w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-2-300x200.png.webp 300w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-2-768x513.png.webp 768w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-2-400x267.png.webp 400w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-2-800x534.png.webp 800w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-2-832x556.png.webp 832w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2026\/02\/strong-pw-mfa-inner-2-150x100.png.webp 150w\" sizes=\"auto, (max-width: 1201px) 100vw, 1201px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What Users Should Secure First<\/strong>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you manage a single website, prioritise:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hosting control panel access&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>WordPress admin accounts&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Database user accounts&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Email accounts associated with the domain&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>FTP\/SFTP credentials&nbsp;&amp; adding whitelists where applicable&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For resellers, the impact is broader. You should&nbsp;prioritise:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Strong, unique passwords for all&nbsp;<a href=\"https:\/\/docs.20i.com\/my-services\/two-factor-authentication-my20i\" target=\"_blank\" rel=\"noreferrer noopener\">admin<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/docs.20i.com\/my-services-my-account\/enforce-two-factor-authentication-on-stackcp-users-or-team-members\" target=\"_blank\" rel=\"noreferrer noopener\">team member<\/a>&nbsp;accounts&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>WordPress admin accounts&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Database user accounts&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>MFA&nbsp;<a href=\"https:\/\/www.20i.com\/blog\/optionally-enforce-2fa-for-stackcp-users-team-members\/\" target=\"_blank\" rel=\"noreferrer noopener\">enabled&nbsp;&amp; enforced<\/a>&nbsp;on StackCP users&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>FTP&nbsp;<a href=\"https:\/\/docs.20i.com\/ftp\/connect-ftp\" target=\"_blank\" rel=\"noreferrer noopener\">lock is enabled<\/a>&nbsp;or an effective whitelist is in place&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enforce the&nbsp;<a href=\"https:\/\/gds-way.digital.cabinet-office.gov.uk\/standards\/principle-least-access.html#principle-of-least-privilege\" target=\"_blank\" rel=\"noreferrer noopener\">principle of least privilege<\/a>&nbsp;(PoLP)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Regular audits of who has access and at what level&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">One compromised reseller login can affect many, potentially all,&nbsp;customers at once.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Automated attacks do not discriminate; enabling MFA takes far less time than recovering a compromised account and prevents irreparable damage.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Conclusion<\/strong>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Strong passwords and&nbsp;MFA&nbsp;are not advanced security&nbsp;features;&nbsp;they are&nbsp;crucial&nbsp;protections&nbsp;in modern&nbsp;account security.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For end users, they protect your website and data.&nbsp;<br>For resellers, they protect your customers, your reputation, and your business.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A few minutes spent strengthening credentials can prevent hours&nbsp;or days&nbsp;of cleanup later.&nbsp;We recommend that&nbsp;you&nbsp;conduct&nbsp;and audit,&nbsp;review your passwords and enable&nbsp;MFA wherever possible.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We also recommend&nbsp;reading up on&nbsp;<a href=\"https:\/\/www.20i.com\/blog\/the-most-common-cyber-threats-in-web-hosting\/\" target=\"_blank\" rel=\"noreferrer noopener\">the most common cyber threats in the hosting industry<\/a>.&nbsp;<\/p>\n\n\n<div class='code-block code-block-2' style='margin: 8px 0; clear: both;'>\n\n<div class='ai-rotate ai-unprocessed ai-rotate-2-21918394' data-shares='WzUwLDEwMF0=' style='position: relative;'>\n<div class=\"ai-rotate-option\" data-index=\"1\" data-name=\"UmVzZWxsZXIgSG9zdGluZw==\" data-code=\"Cjxocj4KPGJyIC8+CjxhIGhyZWY9Imh0dHBzOi8vd3d3LjIwaS5jb20vcmVzZWxsZXItaG9zdGluZyIgdGFyZ2V0PSJfYmxhbmsiPjxpbWcgc3JjPSJodHRwczovL3d3dy4yMGkuY29tL2Jsb2cvd3AtY29udGVudC91cGxvYWRzLzIwMjYvMDMvQmxvZy1BZC1SZXNlbGxlci0xMjAweDYyNS0xLnBuZyIgbG9hZGluZz0ibGF6eSIgYWx0PSJVbmxpbWl0ZWQgUmVzZWxsZXIgSG9zdGluZyI+PC9hPgoK\">\n<\/div>\n<div class=\"ai-rotate-option\" data-index=\"2\" data-name=\"MjBpIFlvdVR1YmU=\" data-code=\"Cjxocj4KPGJyIC8+CjxhIGhyZWY9Imh0dHBzOi8vd3d3LnlvdXR1YmUuY29tL0AyMGlob3N0aW5nP3N1Yl9jb25maXJtYXRpb249MSIgdGFyZ2V0PSJfYmxhbmsiPjxpbWcgc3JjPSJodHRwczovL3d3dy4yMGkuY29tL2Jsb2cvd3AtY29udGVudC91cGxvYWRzLzIwMjYvMDUvMjBpLVlvdVR1YmUtMTIwMHg2MjUtMS5wbmciIGxvYWRpbmc9ImxhenkiIGFsdD0iMjBpIFlvdVR1YmUiPjwvYT4=\">\n<\/div>\n<\/div>\n<script>if (typeof ai_js_code == 'boolean') {var ai_block_div = document.querySelector ('.ai-rotate-2-21918394'); ai_process_rotation (ai_block_div); ai_block_div.classList.remove ('ai-rotate-2-21918394');};<\/script>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"In the&nbsp;web hosting&nbsp;industry, security breaches rarely start with someone&nbsp;\u201chacking\u201d their way&nbsp;into&nbsp;the servers.&nbsp;&nbsp; Far more often, they begin with&nbsp;attacks&hellip;","protected":false},"author":34,"featured_media":18651,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"ub_ctt_via":"","_monsterinsights_skip_tracking":false,"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[288],"tags":[],"class_list":["post-18648","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security","cs-entry"],"featured_image_src":"https:\/\/www.20i.com\/blog\/wp-content\/uploads\/2026\/02\/strong-pw-mfa-no-title-scaled.png","author_info":{"display_name":"Arron C","author_link":"https:\/\/www.20i.com\/blog\/author\/arroncruse\/"},"_links":{"self":[{"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/posts\/18648","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/comments?post=18648"}],"version-history":[{"count":3,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/posts\/18648\/revisions"}],"predecessor-version":[{"id":18789,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/posts\/18648\/revisions\/18789"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/media\/18651"}],"wp:attachment":[{"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/media?parent=18648"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/categories?post=18648"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/tags?post=18648"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}