💧 What Is a Password Spray Attack? How It Works and How to Stop It in 2026
On this page
Microsoft blocked more than 4,000 password attacks per second in 2023, according to the company's Digital Defense Report. That number has risen every year since. A large share of those attempts are not brute force. They are password spray attacks, built specifically to never trip an account lockout.
A password spray attack is an authentication attack where an adversary tries one or two commonly-used passwords against a very large list of accounts, deliberately staying below the lockout threshold on any single account. The technique avoids the "too many failures on one account" alert that conventional brute force triggers, which makes it far harder to catch in real time.
What Is a Password Spray Attack?
The name captures the mechanics exactly. Instead of hammering a single account with thousands of guesses, the attacker "sprays" one guess across an entire directory of usernames. If a company has 8,000 accounts and just 0.5% of employees use the password Welcome1, that is 40 compromised logins without a single lockout firing.
Password spray is distinct from two closely related attacks:
| Attack type | Password pool | Account pool | Lockout risk |
|---|---|---|---|
| Password spray | 1-5 common passwords | Thousands of accounts | Very low by design |
| Brute force | Every possible combination | One account | High (triggers quickly) |
| Credential stuffing | Millions of known breached pairs | Many sites and accounts | Medium (uses confirmed pairs) |
Spraying guesses. Stuffing confirms. Brute force grinds. All three are separate problems requiring different defences.
How Password Spray Attacks Work
A typical spray campaign runs in four stages.
Stage 1: Harvest usernames
Attackers start by building a list of valid account names for the target. Corporate email formats are predictable: [email protected]. LinkedIn, the company website, and automatic email-harvesting tools hand attackers hundreds to thousands of targets in under an hour. Tools such as o365spray or MSOLSpray can pre-validate which addresses are active Microsoft 365 accounts before any spray attempt begins, removing dead accounts and improving the hit rate.
Stage 2: Choose target passwords
The password list stays deliberately short. Attackers pick values that are likely to match the organisation's password policy while remaining common enough that some users will have chosen them. For October 2026, typical spray candidates include: October2026!, Welcome1, P@ssword1, Summer2026!, CompanyName1. NIST SP 800-63B Section 5.1.1.2 notes that users routinely substitute @ for a and append ! to meet complexity requirements, which makes these character-swap patterns highly guessable even when they pass a complexity checker.
Stage 3: Spray slowly
The attacker submits one password attempt per account, then waits. Most Active Directory and cloud identity systems lock accounts after 5 to 10 failed attempts within a fixed window. By staying at one attempt per account per 30 to 60 minutes, the attacker never triggers that threshold. Automated tools handle the pacing, distributing requests across multiple IP ranges and time zones to avoid rate-limiting. A spray across 10,000 accounts at one guess every 45 minutes generates no lockouts whatsoever.
Stage 4: Access and persist
A successful hit gives the attacker a real credential. In Microsoft 365, that means immediate access to email, SharePoint, Teams, and OneDrive. From that foothold, attackers typically set inbox forwarding rules to an external address, search for wire transfer or invoice conversations for business email compromise (BEC) fraud, and probe for privileged accounts to escalate into.
Why Password Spraying Succeeds
Two structural problems keep enterprises exposed.
First, standard password complexity policies produce predictable output. A rule requiring eight characters, one uppercase letter, one number, and one symbol generates Welcome1! at a remarkable rate across large workforces. The NCSC's technical guidance on authentication states clearly that lockout policies "offer no protection against low-and-slow credential attacks that distribute attempts across many accounts." Password spray is the canonical example of exactly that technique.
Second, most organisations skip the step NIST explicitly recommends. NIST SP 800-63B Section 5.1.1.2 states that identity verifiers must compare new passwords against a list of commonly-used, expected, or compromised values at the point of enrollment and each password change. A company that does not maintain this blocklist will keep accepting October2026! from its employees month after month, giving attackers a reliable seasonal target to spray.
Neither problem has anything to do with hacking skill. Both are solved by policy and tooling, not by buying expensive security products.
Who Uses Password Spray Attacks
CISA Advisory AA23-049A names Russian state-sponsored threat actors, specifically the group tracked as APT29 (Cozy Bear), as frequent users of password spraying against US and allied government networks, defence contractors, and critical infrastructure. The advisory notes that the technique requires minimal technical sophistication and that a single compromised account is enough to provide initial access to an entire network.
Nation-state actors are not the only concern. Financially motivated criminals run spray campaigns against Microsoft 365 tenants at scale, hunting for accounts they can monetise through BEC fraud. The FBI IC3 consistently ranks BEC as the costliest cybercrime category by dollar loss, with reported losses rising every year across its annual Internet Crime Reports. A significant share of those incidents trace back to accounts first compromised through password spraying or credential stuffing rather than sophisticated technical exploitation.
Common Targets in 2026
Any internet-facing authentication endpoint is a candidate for spraying. The most actively targeted systems include:
- Microsoft 365 and Entra ID: The top target by volume. Legacy authentication protocols (Basic Auth, IMAP, POP3, SMTP AUTH) remained in use at many organisations long after Microsoft retired them for new tenants. Legacy auth bypasses MFA entirely, so a sprayed password becomes immediately usable with no second factor needed.
- Active Directory Federation Services (ADFS): On-premises ADFS endpoints exposed to the internet receive continuous spray traffic. The
/adfs/ls/and/adfs/services/trust/endpoints do not apply throttling by default, leaving them open to sustained low-volume attempts. - VPN portals: Cisco ASA, Fortinet FortiGate, and Pulse Secure login pages are targeted wherever organisations lack MFA on remote access. CISA has flagged this pattern in multiple advisories from 2023 to 2026.
- OWA (Outlook Web Access): Legacy Exchange deployments that still expose OWA without MFA offer a clean, publicly accessible login page with no built-in spray detection.
How to Detect a Password Spray Attack
Standard lockout alerts will not fire. Detection requires examining patterns across accounts rather than depth within a single account.
Key indicators in authentication logs:
- A large number of accounts each showing exactly one failed login within a short window (for example, 400 accounts with one failure each in under five minutes)
- Authentication failures clustered on the same password value across many distinct accounts
- Failures from a single IP address or small subnet that then shifts (attackers rotate through residential proxy pools to defeat IP-based blocking)
- A spike in Microsoft Entra ID error codes
AADSTS50126(invalid credentials) orAADSTS50055(expired password) across many sign-in events in a short period
Microsoft Sentinel, Splunk, and most SIEM platforms ship with out-of-the-box detection rules for this pattern. The MITRE ATT&CK framework classifies password spraying under T1110.003 (Brute Force: Password Spraying), and the detection guidance there is a practical starting point for custom alert rules.
How to Stop Password Spray Attacks
1. Use unique, non-predictable passwords for every account
The most direct defence is removing predictable passwords from your accounts. A random 16-character password like k#7mWqZx!pLn3vRj will never appear on an attacker's spray list, regardless of how many seasonal variations they try. Generating and managing passwords of that complexity across dozens of accounts is not realistic without a password manager.
NordPass generates cryptographically random passwords and stores them encrypted across all your devices. It also scans for your credentials in known data breaches, alerting you before an attacker spray-tests a compromised account. For organisations, NordPass Business adds centralised password policy enforcement and audit logs so administrators can verify that predictable patterns have been eliminated.
2. Enable multi-factor authentication on every account
MFA is the highest-value single control against password spray. A successfully guessed password cannot be used without the second factor. CISA's Cybersecurity Performance Goals list phishing-resistant MFA (FIDO2 hardware keys or passkeys) as the top priority for all organisations. SMS-based MFA is better than nothing but is vulnerable to SIM-swapping. App-based TOTP codes and hardware keys (YubiKey, FIDO2 security keys) both block spray-obtained credentials from being usable.
3. Disable legacy authentication protocols
Legacy protocols such as Basic Auth, IMAP, and SMTP AUTH bypass conditional access policies and MFA. Microsoft retired Basic Auth for Exchange Online in October 2022, but hybrid and on-premises deployments still expose these endpoints at many organisations. Audit your environment and block every authentication path that cannot enforce MFA. The NIST SP 800-63B guidance provides the baseline standard for what constitutes acceptable digital identity verification.
4. Implement smart lockout and conditional access
Microsoft Entra ID Smart Lockout applies lockout logic across Microsoft's global network, not just your tenant. It blocks IP addresses with known spray history before they reach your accounts. Conditional access policies can require MFA for all sign-ins from unfamiliar locations or new devices. Both features are available in Entra ID P1 and above and take minutes to configure once the policy is designed.
5. Compare passwords against a known-compromised blocklist
NIST SP 800-63B requires that identity providers check new passwords against known-bad lists at enrollment and at each change. Microsoft Entra ID does this automatically via its global and custom banned password lists. On-premises Active Directory deployments need the Azure AD Password Protection agent installed to gain the same protection. The custom list is where company-specific terms (company name, product names, city names) belong so they cannot be used as spray targets.
6. Protect endpoints from credential-stealing malware
Password spraying targets authentication endpoints, but attackers also collect account lists from infostealers installed on user devices. Removing that malware removes the supply chain that feeds future spray campaigns. Kaspersky Premium provides real-time detection of keyloggers and credential-harvesting malware that capture passwords before they even reach the keyboard buffer.
Frequently Asked Questions
What is a password spray attack?
A password spray attack is a brute force technique where an attacker tries a small number of commonly-used passwords against a large list of user accounts. Unlike traditional brute force, spraying attempts only one or two passwords per account, deliberately staying below lockout thresholds to avoid detection.
How is a password spray attack different from credential stuffing?
Password spraying uses common passwords against many unknown accounts. Credential stuffing uses known username-password pairs stolen from data breaches and tests those exact pairs on other sites. Spraying guesses. Stuffing confirms. Both require different defences.
Who typically conducts password spray attacks?
CISA Advisory AA23-049A documents Russian state-sponsored groups, including APT29 (Cozy Bear), using password spraying to access government and corporate networks. Cybercriminal groups also use it extensively to compromise Microsoft 365 tenants for BEC fraud. The technique requires almost no technical skill, which is part of its appeal.
Which passwords do attackers try first in a spray attack?
Attackers start with the current month and year combined with common patterns: October2026!, Welcome1, Password1, Summer2026!, P@ssword1. They also try the company name followed by a number or symbol. The goal is a password that passes a typical complexity checker while being predictable enough that a measurable percentage of a large workforce will have chosen it.
Does multi-factor authentication stop password spray attacks?
Yes. Even if an attacker guesses a correct password through spraying, MFA blocks the login because they cannot provide the second factor. CISA and Microsoft both cite MFA as the single most effective control against password spray attacks on enterprise accounts. Use phishing-resistant MFA (FIDO2 keys or passkeys) where possible; TOTP app codes are acceptable, and SMS is better than nothing.