Password Spray Attacks: The Silent Credential Threat

Why attackers don't need to brute-force one account — and how a few common passwords across many accounts can bring down an enterprise.

5 min read

The Spray, Not the Brute

A brute-force attack tries many passwords against one account: alice@corp.com / password1, password2, password3…

A password spray flips the model: one common password against many accounts:

alice@corp.com   → Winter2026!
bob@corp.com     → Winter2026!
charlie@corp.com → Winter2026!
...

This is harder to detect. A single failed login per account rarely triggers lockout or alerts — but across 10,000 employees, a spray with Spring2025! might hit 50-100 accounts that use that exact password.

Why Password Spraying Works

  1. Users predictably cycle passwords — Spring2024! → Summer2024! → Fall2024! → Winter2024!. Attackers know the pattern.
  2. Complexity requirements produce predictability — Password1! satisfies every rule (uppercase, lowercase, number, symbol) and is extremely common.
  3. Lockout policies have a blind spot — 1 failed attempt per account per hour doesn’t trigger lockout (MITRE T1110.003). But an attacker can try 100,000 accounts.
  4. MFA fatigue — Even when MFA is enabled, users sometimes approve unexpected push notifications (“It’s probably IT testing again”).

Real-World Impact

Some of the biggest breaches in recent years started with password spraying:

  • Microsoft (2023-2024) — Russian state-sponsored group (APT29/Cozy Bear) sprayed hundreds of Microsoft corporate accounts. A handful were compromised before MFA could intervene. (Microsoft DART report)
  • RSA SecurID (2011) — Spear-phishing + password spray against RSA employees led to the theft of SecurID seed data, compromising millions of tokens.

Defences

DefenceHow It Helps
Phishing-resistant MFA (FIDO2)A password alone is never enough. FIDO keys prevent credential theft entirely.
Conditional AccessBlock logins from unusual locations, devices, or IP ranges (Azure AD Conditional Access).
PasswordlessEliminate passwords entirely (passkeys, Windows Hello, smart cards).
Account lockout tuningLock after 5-10 failures — even across IPs.
Anomaly detectionSudden spikes in failed logins (even 1 per account) across many accounts.
Block known breached passwordsAzure AD Password Protection, Have I Been Pwned.
Educate about patterns”Don’t change Password1! to Password2! — that’s the same password.”

Detection: What to Look For

In your SIEM or IdP logs:

  • Many accounts with ErrorCode: InvalidPassword from similar source IPs in a short window
  • Successful logins from unusual geo-locations immediately after a failed attempt on the same account
  • A single user-agent string across logins from different accounts

Detection strategies often rely on correlating otherwise sub-threshold failures across accounts (Trimarc research, CISA guide).

The Passwordless Endgame

The ultimate defence against password spray is no password at all. FIDO2 passkeys, smart cards (PKI), and biometric authentication eliminate the shared secret that makes spraying possible. This is the direction the industry is moving — and fast.


Password spraying is low-effort and high-impact. It preys on human nature, not technical vulnerabilities. The fix is multi-layered: MFA, anomaly detection, and a long-term plan to go passwordless.

References