Password spraying
TL;DR
Password spraying tries one common password against many accounts, so it slips under per-account lockout thresholds. It works depressingly often against exposed logins without MFA. The defences are MFA, monitoring for the pattern, and sensible lockout.
What it is
Instead of hammering one account with many passwords (which locks it out), spraying tries a single likely password — a seasonal one, the company name and a year — across a whole list of users. Low and slow, it stays under the radar.
How it works
Given a list of valid usernames (often from OSINT) and an exposed login — a webmail portal, a VPN, a cloud tenant — the attacker tries one password per account, waits, and tries the next. Somewhere in a big enough org, someone is using the obvious one.
How to detect it
- Many failed logins spread across different accounts from one source, rather than many against one.
- Failed-then-successful patterns, and logins from unusual locations.
How to defend
- MFA everywhere external — it defeats spraying even when a password is right.
- Ban weak and predictable passwords, and monitor for the spread-out failure pattern.