Password Spraying Attacks Jump 155-Fold as Attackers Hunt for MFA Blind Spots
Huntress logged more than 81 million login attempts in a single two-week campaign, with attackers targeting old sign-in methods that skip multi-factor checks.

Key points
- Huntress recorded a 155-fold rise in password spraying attacks in the first half of 2026.
- One campaign generated more than 81 million login attempts across two weeks.
- Attackers targeted legacy authentication protocols that bypass modern multi-factor prompts.
- Gaps in multi-factor authentication (MFA) policies left some login paths completely unprotected.
- Defenders are urged to disable legacy sign-in methods and audit conditional access rules.
Security firm Huntress says attackers are pounding corporate login pages at a scale not seen before. Its researchers logged a 155x jump in password spraying during the first half of 2026, according to reporting first surfaced by BleepingComputer.
Password spraying is a simple trick with a nasty payoff. Instead of guessing many passwords against one account (which usually triggers a lockout), the attacker tries one common password against thousands of accounts. Slow, quiet, and often invisible to basic alerts.
One campaign alone fired off more than 81 million login attempts in two weeks. That is roughly 67 attempts every second, aimed at whatever corporate accounts the attackers could enumerate.
How are the attackers getting past MFA?
They are not, in most cases. They are going around it. Multi-factor authentication (MFA), the extra code or app prompt on top of a password, only protects the login paths it is switched on for. Older sign-in methods, called legacy authentication, often skip that second check entirely.
Huntress found attackers deliberately hitting those older protocols. Think of the mail-fetching plumbing that email clients used a decade ago: still switched on inside many tenants, still accepting a username and password with nothing else asked.
Where MFA policies had gaps, sometimes a single unprotected app, sometimes a forgotten service account, the sprayers walked in. No prompt, no push notification, no warning to the user.
Who is being targeted?
Mostly small and mid-sized businesses, based on Huntress telemetry, though the technique works against any organisation with cloud email or single sign-on. The attackers are not picky. They spray, they see which accounts answer, and they come back later to log in cleanly.
Once inside, the usual playbook follows: read the mailbox, set up forwarding rules, look for invoices to hijack, and pivot to whatever cloud apps the account can reach.
What the numbers look like
| Metric | Figure |
|---|---|
| Rise in password spraying, H1 2026 | 155x |
| Login attempts in one campaign | 81 million+ |
| Duration of that campaign | 2 weeks |
| Primary weakness abused | Legacy authentication and MFA gaps |
What should defenders do this week?
Start by assuming legacy authentication is still on somewhere in your tenant, because it usually is. Microsoft's guidance on blocking legacy authentication in Microsoft Entra ID is the obvious first stop for Microsoft 365 shops.
Then audit conditional access. Every app, every service account, every break-glass account. If a login path exists that does not require MFA, an attacker will find it before you do.
A few practical moves:
- Turn off IMAP, POP3, and basic auth for Exchange Online unless a documented app genuinely needs them.
- Enforce MFA on every user, including service and shared mailboxes where technically possible.
- Watch for slow, distributed login failures across many accounts. That is the fingerprint.
- Rotate passwords for any account that shows up in spray telemetry, even if the login failed.
Why this matters for ordinary staff
If your work account suddenly asks you to approve a login you did not start, do not tap approve to make it go away. That prompt is the attackers testing a password they already have. Report it, then change the password.
Attackers are not doing anything clever here. They are betting that somewhere in your organisation, one old login door was left unlocked. On current numbers, that bet is paying off.



