Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

RDP password-guessing activity remained high in 2021, but the headline totals are vendor telemetry—not a count of confirmed break-ins. Kaspersky reported billions of detections in 2020 and hundreds of millions in February 2021; ESET later reported a sharp rise in RDP attack attempts across its 2021 telemetry. Those figures show sustained pressure on exposed Remote Desktop services, not how many organizations were compromised.

What is an RDP brute-force attack?

Remote Desktop Protocol (RDP) is a Microsoft proprietary protocol commonly used to connect to Windows workstations and servers remotely. A brute-force attack is an attempt to gain access by trying passwords against an RDP service. If an attacker guesses valid credentials, they may be able to log in remotely; the published totals do not say how often guessing succeeded.

In this coverage, “attacks” can mean detections, password guesses, or attack attempts, depending on the vendor and report. They are not a global census, a count of unique organizations, or proof of successful intrusions.

How many RDP attacks were reported in 2021?

The available figures indicate persistent, high-volume activity, but they come from different vendors and measurement windows. They should not be joined into one continuous trend line because the sources do not establish that their telemetry methods are equivalent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Source and period Reported measure What the figure means
Kaspersky, worldwide, January–November 2019 969 million RDP brute-force detections reported by Kaspersky. Source
Kaspersky, worldwide, January–November 2020 3.3 billion; 242% higher year over year RDP brute-force detections reported by Kaspersky. Source
Kaspersky figures reported by Dark Reading, February 2021 377.5 million, compared with 91.3 million at the start of 2020 Brute-force attacks, as described in Dark Reading’s March 17, 2021 account. The same account reported a worldwide February-to-March 2020 rise from 93.1 million to 277.4 million. Source
ESET, T1 2021 27 billion; 60% above T3 2020 RDP password guesses in ESET telemetry. Source
ESET, May–August 2021 55 billion; 104% above T1 2021 RDP brute-force attacks reported by ESET. Source
ESET, 2021 telemetry, reported in 2022 288 billion; 897% higher than 2020 RDP attacks reported across ESET’s 2021 telemetry. ESET also said the average daily number of unique clients reporting attacks fell from 161,000 in T2 to 153,000 in T3 2021. These client counts are not attack totals. Source

Because the sources use differing telemetry and labels, the table provides context rather than a direct comparison between Kaspersky and ESET. In particular, the number of reporting clients is a separate measure from the volume of attacks.

Why were RDP attacks increasing?

In its March 2021 account, Dark Reading described researchers’ view that remote-work adoption expanded the opportunity for attackers: some organizations had hastily configured remote services, and weak passwords made exposed accounts more susceptible to guessing. Attackers were seeking to capitalize on the increased use of remote access.

Kaspersky researcher Maria Namestnikova emphasized password complexity, and also recommended corporate VPN access, additional authentication, and disabling RDP when it is not needed. These steps address different weaknesses: credentials, exposure, and unnecessary access.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can I secure RDP access?

Use layered controls to reduce the chance of an attacker reaching RDP and limit harm if another control fails. Kaspersky’s business guidance recommends the following measures:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Turn off RDP when it is not in use. Remove an unnecessary remote-access service rather than leaving it exposed.
  • Restrict public access. Prevent connections to RDP from public networks when they are not required. Use an appropriate secure business gateway, such as a corporate VPN, for authorized remote access.
  • Strengthen authentication. Use complex, unique passwords and add another authentication factor where available. Password complexity alone does not make a publicly exposed service safe.
  • Patch the access path. Promptly update systems and devices, including VPN products used as gateways.
  • Watch for activity after login. Monitor for lateral movement and data exfiltration; an account login is not the only sign of compromise.
  • Keep accessible backups. Maintain backups that can be reached quickly if systems or data need recovery.
  • Train employees and use protective monitoring. Kaspersky also recommends employee training and protective services such as endpoint detection and response (EDR) or managed detection and response (MDR).

These are risk-reduction layers, not guarantees against compromise. Choose remote-access controls that fit your organization’s systems and support requirements.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.