Surge in Password Spraying Attacks Exploits MFA Gaps

Surge in Password Spraying Attacks Exploits MFA Gaps

First seen 19 Aug 2026, 14:41 UTC Bleepingcomputerwww.huntress.comFeeds.4Sysops 90% similarity 71.0

Article Content

Browse articles
ThreatCluster

In the first half of 2026, Huntress reported a 155x increase in password spraying attacks, primarily targeting Microsoft's Azure CLI. This surge was driven by a campaign from LSHIY LLC, resulting in over 81 million login attempts and 78 account compromises within two weeks. Attackers exploited legacy OAuth behavior, specifically Resource Owner Password Credentials (ROPC), which bypassed multi-factor authentication (MFA) measures. Despite the high volume of attacks, no post-compromise activity was observed, suggesting that attackers may have been validating credentials for resale. The campaign highlighted significant gaps in MFA configurations, particularly in relation to Conditional Access Policies (CAP). Security experts emphasize the need for organizations to review their authentication methods to mitigate such risks.

Key Points: • Huntress observed a 155x increase in password spraying attacks in 2026. • Over 81 million login attempts targeted Azure CLI users, compromising 78 accounts. • Attackers exploited ROPC to bypass MFA, revealing significant security gaps.

ThreatCluster AI How this analysis works

Timeline

2026-06-22
Spike in password spraying attacks observed
Huntress recorded over 81 million login attempts in a two-week period, linked to the LSHIY campaign.
Huntress
2026-08-19
Huntress reports on MFA gaps
The surge in password spraying attacks exploited MFA gaps, particularly through legacy OAuth methods.
Bleepingcomputer
2026-08-19
81 million Azure login attempts reported
A password-spraying campaign generated over 81 million login attempts against Azure CLI users, exposing MFA vulnerabilities.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story