In a brute-force attack, the attacker's software rapidly tries different passwords against an account: dictionary words, common passwords or passwords leaked from other sites. Common targets are exposed remote desktop (RDP), VPN and email.
Defences: strong and unique passwords, MFA, temporary account lockout after repeated failures, and hiding remote access from the internet behind a VPN.
A server had RDP open to the internet with thousands of login attempts logged every night — access was moved behind a VPN.