Password spraying attacks surge 155x as hackers exploit MFA gaps
Summary
Huntress reported a 155x surge in password spraying attacks during the first half of 2026. These attacks exploited legacy authentication methods and vulnerabilities in Multi-Factor Authentication (MFA) policies, leaving some login processes exposed. One campaign alone resulted in over 81 million login attempts within a two-week period.
IFF Assessment
The surge in password spraying attacks and exploitation of MFA gaps indicates an increasing threat to account security, making it bad news for defenders.
Defender Context
The significant increase in password spraying attacks highlights the persistent threat of credential stuffing and the need for robust MFA implementation that covers all authentication flows. Defenders should regularly review and strengthen their authentication policies, ensuring no legacy protocols or bypasses remain vulnerable. Staying vigilant against these widespread brute-force attempts is crucial for preventing account compromise.