Password spraying is a brute-force attack in which a criminal tries a handful of very common passwords against a large list of usernames, rather than bombarding a single account with thousands of guesses. By spreading a few weak passwords — think "Winter2026!" or "Company123" — across hundreds or thousands of accounts, attackers stay under the radar of lockout policies that would normally trigger after a few failed attempts on one account.
The technique has exploded in 2026. Security firm Huntress documented a 155x increase in password spraying attacks in the first half of the year, including a single campaign that generated more than 81 million login attempts in roughly two weeks and compromised dozens of accounts across dozens of organizations. What makes the surge alarming is not sophistication — password spraying is old and simple — but scale, automation, and the fact that it keeps working against enterprises that believed they were protected.
For IT managers and CIOs, password spraying matters because it targets the identity layer, which has quietly become the primary battleground of enterprise security. Attackers no longer need to breach a firewall when they can simply log in with valid credentials. That is why a modern managed cybersecurity program treats identity as the new perimeter, monitoring authentication events in real time rather than trusting the network edge alone.
The reason password spraying still succeeds in 2026 is that many enterprises have multi-factor authentication (MFA) enabled but leave legacy authentication paths wide open. MFA only protects the login flows it actually covers. When an older protocol bypasses the interactive sign-in prompt, MFA never gets a chance to challenge the attacker.
The clearest example is Resource Owner Password Credentials (ROPC), a legacy OAuth grant that was deprecated in OAuth 2.1. ROPC sends a username and password straight to the token endpoint with no interactive prompt, so it supports neither MFA nor single sign-on. In the 81-million-attempt campaign, attackers abused exactly this flow through a widely used command-line tool. Many victim organizations had MFA deployed, but their Conditional Access Policies were never configured to cover the ROPC path — a blind spot that turned a "protected" tenant into an open door.
This is a governance problem as much as a technical one. Enterprises accumulate legacy protocols, service accounts, and command-line tools over years of growth, and few maintain a complete inventory of every authentication path into their Microsoft 365 and identity environment. Password reuse compounds the risk: when the same weak password guards email, VPN, and cloud consoles, a single successful spray can cascade across the business. Closing these gaps requires visibility into how, and through which protocols, users actually authenticate — something a security operations center is built to provide.
Password spraying works by inverting the traditional brute-force model: instead of many passwords against one account, attackers use one password against many accounts, then rotate slowly to avoid detection. Understanding the sequence helps enterprises know where to intervene.
First, attackers harvest usernames — often just corporate email addresses scraped from social networks, data breaches, or a company's own website, since most organizations use a predictable firstname.lastname format. Second, they select a small set of high-probability passwords based on seasons, sports teams, company names, and the local language. Third, they choose an entry point that avoids MFA, such as a legacy protocol, an API, or a command-line tool that can be scripted for volume.
Fourth, they spray: each password is tried once per account across the whole list, then the tool pauses before the next password to stay beneath lockout thresholds and rate limits. Fifth, when a login succeeds, the attacker validates the session, escalates privileges, and moves laterally — reading email, exfiltrating data, or planting forwarding rules and OAuth grants for persistence.
The defensive lesson is that each stage is detectable. A pattern of single failed logins spread across hundreds of accounts, authentication from unusual geographies, or a spike in legacy token requests are all high-fidelity signals. A zero trust access model that verifies every request — combined with continuous monitoring — catches the spray before it becomes a breach.
Enterprises that close their legacy authentication and MFA gaps gain far more than protection against a single attack technique — they build a resilient, identity-first security posture that pays dividends across the business. The first benefit is direct risk reduction: disabling legacy protocols and enforcing Conditional Access on every login flow eliminates the exact blind spots the 2026 campaigns exploited.
The second benefit is operational visibility. When authentication is monitored around the clock, security teams see credential attacks as they unfold and can respond in minutes rather than discovering a breach weeks later. A managed detection and response service turns raw authentication logs into prioritized, actionable alerts, so lean internal teams are not left triaging millions of events by hand.
The third benefit is business continuity and compliance. Credential-based breaches are among the most expensive and disruptive incidents an enterprise can suffer, and regulators increasingly expect demonstrable identity controls. Strong MFA coverage, phishing-resistant authentication, and documented monitoring help satisfy frameworks such as ISO 27001 and SOC 2 while reducing cyber-insurance premiums.
Finally, closing these gaps supports secure growth. As organizations adopt cloud platforms, remote work, and unified communications, a hardened identity foundation lets them expand confidently. Pairing that foundation with resilient IT managed services and cloud backup ensures that even if an account is compromised, the business can recover quickly and completely.
HIT Communications helps enterprises across Latin America, the United States, and Europe close identity gaps before attackers find them. With more than 30 years of experience in enterprise connectivity, telephony, and security, HIT combines the network, communications, and cybersecurity expertise needed to defend the modern identity perimeter end to end.
HIT's managed cybersecurity services — including a 24/7 security operations center, SIEM, and managed detection and response — give enterprises continuous visibility into authentication activity, so password spraying and credential-stuffing campaigns are caught in real time. For organizations standardizing on Microsoft, HIT's Microsoft Teams and cloud telephony solutions are deployed with identity best practices built in, and its SASE and zero trust connectivity enforce least-privilege access across every site and user.
Because HIT delivers connectivity, voice, and security as an integrated portfolio, enterprises get a single partner accountable for the entire attack surface — not a patchwork of vendors that leaves gaps between them.
Password spraying's 155x surge in 2026 is a clear signal: the identity layer is now the enterprise's most contested frontier, and legacy authentication is the crack attackers are pouring through. The good news is that the fixes are well understood — disable deprecated protocols, extend MFA and Conditional Access to every login flow, enforce strong and unique passwords, and monitor authentication continuously.
The organizations that act now, before a spray finds their blind spot, will avoid the cost and disruption of a credential-based breach. Those that wait are betting that attackers running tens of millions of automated login attempts will simply pass them by.
If you are not certain that every authentication path into your environment is covered, that is exactly the gap worth closing first. Contact HIT Communications to review your identity security posture, close your legacy authentication gaps, and put continuous monitoring in place before the next campaign begins.

Find out how we can transform your business. Talk to one of our experts now!
Get in touch