Brute force attacks increased sharply in March 2026 according to Barracuda Managed XDR.
Barracudas latest Threat Radar shows a clear increase in brute force attacks against network devices during the first quarter of this year. Between January and March 2026, a significant increase was recorded in confirmed authentication attempts targeting, among others, SonicWall and FortiGate devices – and about 88 percent could be traced to the Middle East.
A brute force attack is an attack where an attacker uses automated tools to repeatedly try to guess login credentials until the correct combination is found or the attempts are stopped. During the period February to March, these attacks accounted for 56 percent of all confirmed incidents handled by security services Barracuda Managed XDR.
The attack was strongly concentrated geographically in the Middle East with approximately 88 percent of traffic. Most attack attempts failed and were stopped – either by security tools or because the attackers used invalid login credentials.
At the same time, the report shows that repeated and persistent attempts against network devices increase the risk of intrusion, as a single weak password or poor configuration can in some cases be enough for attackers to succeed.
Organizations may be more vulnerable if they lack adequate access and authentication controls, such as multi-factor authentication, use weak or reused passwords, or do not monitor repeated failed login attempts.
In Threat Radar points Barracuda also on risks associated with older or inactive accounts that have not been deleted, while emphasizing the importance of strong passwords, multi-factor authentication, and limited administrative access.
Threat Radar The report also describes how Qilin ransomware can evolve very quickly after the malware is activated. The report also shows an increase in so-called ClickFix attacks which target organizations. Attacks often begin with a phishing email and rely on social engineering, where the recipient is tricked into clicking a link or copying and pasting text to fix a purported problem. Instead, a malicious command or file is executed.








