One threat actor made more than 81 million login attempts against Microsoft 365 accounts in just two weeks this summer. They succeeded, in part, because the attack looked almost too boring to notice. That’s the paradox of password spraying: it’s a technique so simple it barely resembles an “attack” at all, and yet it remains one of the most persistent methods fraudsters use to break into accounts today.
What password spraying is, and how it differs from other login attacks
Password spraying is an authentication attack that involves a fraudster selecting a short list of commonly used passwords, like default passwords or company-name variations, and tests each one against a large number of usernames, one attempt at a time, before rotating to the next password.
The technique is built around a specific weakness in most account lockout policies. Because a login system typically locks an account only after several consecutive failed attempts on that single account, an attacker who tries just one or two passwords per account and then moves on to the next account entirely never triggers the lockout. And when this is multiplied across thousands of accounts, the statistical odds favor the attacker. In any sufficiently large user population, someone is very likely still using one of the common passwords being tested.
This sets password spraying apart from credential stuffing, which uses real, previously breached username and password pairs rather than a shortlist of common guesses, and from a classic brute force attack, which hammers a single account with many password attempts in a row.
The dangers of password spraying
Password spraying isn’t a theoretical risk. Cybersecurity firm Huntress reported an increase in password spraying attacks by 155-fold across its customer base in the first half of 2026, driven in part by a large campaign targeting Microsoft 365 and Azure environments.
According to reporting from The Hacker News, the threat actor behind that campaign made more than 81 million login attempts between June 12 and June 26, 2026, successfully compromising at least 78 user accounts across 64 organizations. The activity originated largely from an IP range tied to a single hosting provider, and it exploited legacy authentication paths and gaps in conditional access policies that left some login flows without multifactor authentication enforcement. When Huntress later observed the attackers shift to a different hosting provider in July, the volume of spraying attempts climbed right back to where it had been during the original campaign, underscoring how quickly this kind of attack can resume once one avenue closes.
BleepingComputer’s coverage of the same research noted that the campaign specifically exploited older authentication protocols, which do not support modern conditional access controls, giving the attackers a path around MFA policies that would otherwise have stopped them cold.
Why password spraying is so hard to catch
Password spraying is designed from the ground up to look unremarkable. A handful of failed logins scattered across a large user base rarely trips any sort of threshold-based alert, because most detection systems are tuned to flag repeated failures on a single account rather than a low, steady drip of failures spread widely across many of them.
The technique also benefits from how organizations actually manage passwords in practice. Predictable password creation habits, such as a company name plus a season and a year, mean that even a short list of guesses has a real chance of matching at least a few accounts. And because attackers only need a small number of successful logins to gain a foothold, a success rate that looks tiny in percentage terms can still translate into dozens of compromised accounts across a large organization.
Legacy authentication protocols make the problem worse. Systems that predate modern conditional access and MFA enforcement give attackers a way to submit spray attempts that never pass through the checkpoints that newer login systems require.
What effective defense against password spraying looks like
Thankfully, several common practices exist that help to reduce the success rate of password spraying campaigns.
Enforcing multi-factor authentication across every login path, including legacy and programmatic authentication, closes the gap that recent large-scale campaigns have exploited. Smart lockout policies that track failed attempts across an entire tenant, not just per account, catch the low-and-slow pattern that per-account lockouts miss. Banning commonly used passwords at the point of account creation, rather than relying on users to avoid them, removes much of the target list an attacker would otherwise spray against. Retiring legacy authentication protocols that cannot enforce conditional access closes one of the most common paths attackers use to bypass MFA altogether.
Behavioral monitoring adds another layer on top of these controls. A login attempt that matches a known password on the attacker’s list will still look different from a legitimate one once you factor in device history, network reputation, and typical account behavior.
This is where Account Defense comes in. Sift assesses thousands of signals across the user journey and aggregates them into a risk score (referred to as a Sift Score) numbered between 1 to 100, where 1 indicates a trustworthy user and 100 indicates likely fraud, updating in real time as new signals come in. That kind of continuous signal evaluation is built to catch exactly the pattern password spraying relies on: technically valid login attempts that do not otherwise look like the account owner.
Stopping password spraying takes more than lockout rules. Sift uses machine learning to spot fraud attacks early on and keep them from affecting your business. Learn more about how Sift can help your business.
Frequently asked questions
How is password spraying different from a brute force attack?
A brute force attack tests many passwords against one account until it finds a match or gets locked out. Password spraying tests only a few passwords, but spreads those attempts across many accounts, specifically to avoid triggering per-account lockout thresholds.
Can multi-factor authentication fully stop password spraying?
MFA blocks most password spraying attempts, since a correct password alone will not grant access. But attackers have increasingly targeted outdated authentication protocols and gaps in conditional access policies that don’t enforce MFA consistently, so MFA needs to be applied across every login path.
How can I tell if my organization is being targeted by password spraying?
The biggest sign of password spraying is a pattern of failed logins spread out thinly across many accounts rather than concentrated on a few, especially if those attempts originate from a narrow range of IP addresses or a specific hosting provider. Reviewing authentication logs at the tenant level, rather than the individual account level, is usually necessary to spot it.






