Password spraying attacks surge 155x as hackers exploit MFA gaps

Summary

Huntress reported a 155x surge in password spraying attacks during the first half of 2026. These attacks exploited legacy authentication methods and vulnerabilities in Multi-Factor Authentication (MFA) policies, leaving some login processes exposed. One campaign alone resulted in over 81 million login attempts within a two-week period.

IFF Assessment

FOE

The surge in password spraying attacks and exploitation of MFA gaps indicates an increasing threat to account security, making it bad news for defenders.

Defender Context

The significant increase in password spraying attacks highlights the persistent threat of credential stuffing and the need for robust MFA implementation that covers all authentication flows. Defenders should regularly review and strengthen their authentication policies, ensuring no legacy protocols or bypasses remain vulnerable. Staying vigilant against these widespread brute-force attempts is crucial for preventing account compromise.

Read Full Story →