Password spraying attacks surge 155x as hackers exploit MFA gaps — Here’s What Happened

Password spraying attacks surge 155x as hackers exploit MFA gaps — Here’s What Happened

Password spraying attacks jumped 155-fold in early 2026, with millions of login attempts targeting Microsoft cloud accounts. Here’s why reused passwords and MFA gaps can put your accounts at risk.

What Happened?

According to BleepingComputer, Huntress Labs reported a 155-fold increase in password spraying attacks during the first half of 2026.

The BleepingComputer article was sponsored and written by Huntress Labs, a cybersecurity company that investigates and responds to online attacks.

One major campaign targeted Microsoft Azure CLI, a tool administrators use to manage Microsoft cloud services.

In just two weeks in June, Huntress recorded more than 81 million related login attempts and 78 successful account accesses.

Attackers also used username and password combinations stolen in previous data breaches.

That matters because an old password can remain useful to criminals long after the original breach. Many people may not know their login details appeared in an earlier incident.

If you are unsure whether your information was leaked somewhere online, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and Was Any Data Leaked?

Huntress analyzed 23 affected businesses, but the campaign did not appear to target one specific industry.

Eight businesses had no multi-factor authentication, or MFA, in place.

The other 15 used MFA, but their security rules did not cover the sign-in method used by the attackers.

Huntress recorded 78 successful account accesses during one two-week period in June.

However, Huntress said it did not see further activity after those successful logins. The company did not report confirmed theft of files or other business data.

Huntress said the attackers may have been checking which login details still worked so they could potentially be resold. This has not been confirmed.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety

How Hackers Got Around Some MFA Protections

Password spraying works differently from repeatedly guessing passwords for one account.

Instead, attackers try a small number of common or previously stolen passwords across many usernames. This can help them avoid automatic account lockouts.

In this campaign, attackers also used an older Microsoft sign-in method called ROPC.

ROPC allows a username and password to be sent directly for authentication and does not support modern MFA prompts.

As a result, MFA did not stop every login attempt when a company’s security policies failed to cover this older sign-in method.

The attackers also moved between different internet providers and IP addresses, making simple address blocking less effective.