Hackers use programs called bots to attack login pages, trying out many combinations of usernames and passwords to break into a website. Often bots can try as many as hundreds of combinations per minute, using dictionary words and commonly used passwords to break through. Once they succeed, the hacker has open-door access to your website.
On the flip side, strong passwords are difficult to remember, so admin chooses easy-to-remember ones, like pets’ names, birthdays, or even permutations of the word ‘password’.
However, this makes the site security vulnerable to attacks. This information is legitimately available online via social media and other sites, and illegitimately via data breaches or the dark web. The best thing to do is to have a strong, unique password to keep your account, and therefore website, safe.
Note: You need to set strong passwords across your site accounts, which include your user account and hosting account. Admin doesn’t often change the SFTP and database credentials, but if you have done, make sure you set strong passwords for these too.