Back to glossary

PMKID attack

1 min read

The PMKID attack is a technique against WPA2 personal networks that obtains crackable material directly from the access point, without waiting for a client to connect. A single frame from the access point can contain a value derived from the network passphrase, which is then attacked offline.

July 29, 2026
Compartir:

What changed with this technique is the capture requirement. The classical attack on a personal wireless network needs the four way handshake between an access point and a client, which means waiting for someone to connect or forcing a disconnection so they reconnect, and the second option is noisy and disruptive. Here the identifier is requested from the access point directly, and it is derived from the same pre-shared key material, so the offline attack that follows is the same one. It was documented publicly by the authors of the widely used cracking tool, and support has been standard in wireless auditing tooling since.

What has not changed is what decides the outcome. The value is the product of a key derivation function over the passphrase and the network name, so a long random passphrase does not fall and a memorable one does. Network names left at a manufacturer default make it cheaper still, because precomputed tables exist for common ones.

Two scoping notes. It applies to the pre-shared key mode, so an enterprise network authenticating each user separately is not affected, and WPA3 personal changes the handshake so that offline brute force against a captured value is no longer possible, which is the strongest argument for moving to it. In a report we state the capture, the time to recovery and the passphrase length, never the passphrase itself, as part of the wireless testing where passphrase strength is proven rather than assumed.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.