Surge in Password Spraying Attacks Exploits MFA Gaps
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In the first half of 2026, Huntress reported a 155x increase in password spraying attacks, primarily targeting Microsoft's Azure CLI. This surge was driven by a campaign from LSHIY LLC, resulting in over 81 million login attempts and 78 account compromises within two weeks. Attackers exploited legacy OAuth behavior, specifically Resource Owner Password Credentials (ROPC), which bypassed multi-factor authentication (MFA) measures. Despite the high volume of attacks, no post-compromise activity was observed, suggesting that attackers may have been validating credentials for resale. The campaign highlighted significant gaps in MFA configurations, particularly in relation to Conditional Access Policies (CAP). Security experts emphasize the need for organizations to review their authentication methods to mitigate such risks.
Key Points: • Huntress observed a 155x increase in password spraying attacks in 2026. • Over 81 million login attempts targeted Azure CLI users, compromising 78 accounts. • Attackers exploited ROPC to bypass MFA, revealing significant security gaps.