Glossary
Password Spraying
Instead of trying 1000 passwords on one account (which gets locked), password spraying tries one common password like 'Summer2024!' on 1000 accounts. Some will work because people use predictable passwords. It's slow but effective and hard to detect.
What is Password Spraying?
An attack that tries a small number of commonly used passwords against many accounts, avoiding account lockouts that would occur from multiple failed attempts on a single account.
Why Should You Care?
Password spraying bypasses account lockout mechanisms by trying a few common passwords across many accounts, making it significantly harder to detect than traditional brute force against a single account. Successful spraying can grant attackers persistent access to email systems and cloud services, enabling business email compromise, ransomware deployment, and data exfiltration. The distributed, low-and-slow nature of these attacks means they often go unnoticed until after a breach occurs.
Is your business exposed?
Real-World Example
Attackers commonly target Microsoft 365 and other cloud identity platforms with password spraying, cycling through predictable seasonal passwords (like 'Spring2024!') across thousands of accounts while spacing attempts to avoid lockouts. A notable example is the 2024 intrusion into Microsoft attributed to the Russia-linked Midnight Blizzard group, which used password spraying to compromise a legacy account and pivot into corporate systems—showing how even a single successfully sprayed account can lead to a significant breach.
How to Protect Against Password Spraying
- 1.
Enforce strong password policies
- 2.
Require MFA for all accounts
- 3.
Monitor for distributed login failures
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required