Cybersecurity

Password Spraying Attacks Surge 155-Fold as MFA Policy Weaknesses Are Exploited

Huntress observed a 155-fold increase in password-spraying attacks during the first half of 2026, including a campaign targeting Azure CLI that recorded more than 81 million login attempts over two weeks. The campaign exploited an outdated authentication flow that some MFA policies did not cover, resulting in the compromise of 78 accounts.

2026-08-19
3 min read
9 views
فريق تحرير certi.news
Password Spraying Attacks Surge 155-Fold as MFA Policy Weaknesses Are Exploited

Huntress observed a 155-fold increase in password-spraying attacks during the first half of 2026, in a wave that leveraged leaked credentials and legacy authentication paths that are not always protected by multifactor authentication (MFA). The most prominent cases included a campaign targeting the Azure CLI tool used by system administrators to manage Azure and Entra resources.

The activity originated from an IPv6 range controlled by internet hosting company LSHIY LLC. The campaign began months earlier, but in mid-June Huntress recorded more than 81 million login attempts associated with it over two weeks, resulting in the compromise of 78 accounts. The company observed no subsequent activity following the compromises associated with this campaign, while Rich Mozeleski, Huntress’s director of product, suggested that the attacker was verifying the validity of the credentials in preparation for reselling them on the dark web.

How Were the Attacks Carried Out?

Password spraying involves trying a limited number of common or leaked passwords against many accounts, rather than trying a large number of passwords against a single account. This approach helps the attacker avoid lockout thresholds and direct alerts. The process usually begins by collecting valid usernames from corporate websites, LinkedIn, data breaches, and phishing campaigns, followed by preparing a short list of known passwords or passwords associated with the company or seasons.

  • Collecting potential usernames.
  • Preparing a limited list of leaked or common passwords.
  • Trying one password against multiple accounts at a low rate.
  • Using the compromised account for lateral movement, business email compromise, or the theft of additional data.

According to Huntress, the LSHIY campaign combined a broad range of attempts with the reuse of valid username-and-password pairs that had previously been leaked and had not yet been changed. Therefore, a successful attempt was more valuable than randomly guessing a password.

The Vulnerability in the Authentication Path

The attackers also exploited the Resource Owner Password Credentials mechanism, known as ROPC, an outdated OAuth grant that was discontinued in OAuth 2.1. This mechanism sends the username and password directly to the /token endpoint and does not provide modern authentication flows such as MFA or single sign-on (SSO), nor does it display an interactive multifactor authentication prompt.

In practice, this means that a reused password that remains valid can become an active access session even when an organization has enabled MFA through a Conditional Access Policy (CAP), if the policy does not specifically cover the ROPC path. Andrew “Spike” Brandt, Huntress’s lead threat intelligence incident leader, described the mechanism as technically a “method of impersonation,” despite being called an authorization method.

What Changes in Practice?

The campaign demonstrates that enabling MFA in general does not guarantee protection for every login path. Legacy paths or exceptions not covered by access policies may give leaked credentials an opportunity to bypass interactive protection. Huntress said that LSHIY later stopped the attacks from the original IP range and confirmed that the attacker used its Bring Your Own IP (BYOIP) service.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news