Password Spraying Attacks Jump 155-Fold as Attackers Hunt for MFA Blind Spots

Huntress logged more than 81 million login attempts in a single two-week campaign, with attackers targeting old sign-in methods that skip multi-factor checks.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A security operations center with massive wall displays showing login attempt metrics, graphs spiking dramatically upward, failed authentication patterns highli
Share

Key points

  • Huntress recorded a 155-fold rise in password spraying attacks in the first half of 2026.
  • One campaign generated more than 81 million login attempts across two weeks.
  • Attackers targeted legacy authentication protocols that bypass modern multi-factor prompts.
  • Gaps in multi-factor authentication (MFA) policies left some login paths completely unprotected.
  • Defenders are urged to disable legacy sign-in methods and audit conditional access rules.

Security firm Huntress says attackers are hitting corporate login pages at a scale not seen before, logging a 155x jump in password spraying during the first half of 2026, according to reporting first surfaced by BleepingComputer. We've covered Huntress's research fifteen times since May, and the pattern holds: attackers keep finding the doors defenders forgot to lock.

Password spraying is a simple trick with a nasty payoff. Instead of guessing many passwords against one account, which usually triggers a lockout, an attacker tries one common password across thousands of accounts. Quiet. Often invisible to basic alerts.

One campaign alone fired more than 81 million login attempts in two weeks, all of it aimed at whatever corporate accounts the attackers could enumerate.

How are the attackers getting past MFA?

They're not, in most cases. They're going around it. Multi-factor authentication (MFA), the extra code or app prompt on top of a password, only covers the login paths it's switched on for. Older sign-in methods, called legacy authentication, often skip that second check entirely.

Huntress found attackers deliberately targeting those older protocols: the mail-fetching plumbing that email clients used a decade ago, still switched on inside many tenants, still accepting a username and password with nothing else asked.

Where MFA policies had gaps, sometimes a single unprotected app, sometimes a forgotten service account, the sprayers walked straight in. No prompt, no push notification, no warning to the user.

Who is being targeted?

Mostly small and mid-sized businesses, based on Huntress telemetry, though the technique works against any organisation running cloud email or single sign-on. Attackers spray, note which accounts answer, and return later to log in cleanly.

Once inside, the usual playbook follows: read the mailbox, set up forwarding rules, hunt for invoices to hijack, and pivot to connected cloud apps.

What the numbers look like

Metric Figure
Rise in password spraying, H1 2026 155x
Login attempts in one campaign 81 million+
Duration of that campaign 2 weeks
Primary weakness abused Legacy authentication and MFA gaps

What should defenders do this week?

Start by assuming legacy authentication is still on somewhere in your tenant, because it usually is. Microsoft's guidance on blocking legacy authentication in Microsoft Entra ID is the obvious first stop for Microsoft 365 shops.

Then audit conditional access. Every app, every service account, every break-glass account. If a login path exists without MFA, an attacker will find it first.

Practical moves: turn off IMAP and POP3 basic auth for Exchange Online unless a documented app genuinely needs them. Enforce MFA on every user, shared mailboxes included where technically possible. Watch for slow, distributed login failures spread across many accounts; that's the fingerprint. Rotate passwords for any account appearing in spray telemetry, even when the login failed.

Why this matters for ordinary staff

If your work account asks you to approve a login you didn't start, don't tap approve to make it go away. That prompt means attackers are testing a password they already have. Report it, then change the password.

Nothing clever is happening here. Attackers are betting that somewhere in your organisation, one old login door was left unlocked. On current numbers, that bet keeps paying off.

© 2026 Threat Vectr