Account compromises spike when attackers discover they can bypass lockout defenses by distributing login attempts across hundreds of user accounts instead of hammering individual usernames.
Password spraying exploits this gap by testing common passwords like "Password123!" against entire user directories while staying below traditional brute force detection thresholds.
What is password spraying?
Password spraying reverses traditional brute force attack patterns by testing common passwords against large numbers of user accounts. Instead of trying many passwords against one account, attackers use a few popular passwords against hundreds or thousands of usernames.
The technique exploits two common security weaknesses: predictable passwords and lenient lockout policies. Attackers research target organizations to build username lists, then systematically test passwords like "Welcome1" or "Summer2024" across the entire user base.
Spraying attacks follow seasonal patterns, using passwords that match current months, years, or events. Attackers update their password lists quarterly to include new common passwords and seasonal variations. They space attempts carefully to stay below lockout thresholds while maximizing their coverage of the user population.
The attack succeeds because it exploits the statistical reality that some percentage of users will always choose weak, predictable passwords. Even organizations with strong password policies often have legacy accounts, service accounts, or exceptions that create vulnerable targets.
Attack surfaces and threat vectors
Remote Access Portal Exploitation
VPN endpoints and cloud authentication services create massive attack surfaces because they accept connections from any internet location. Office 365, Azure AD, and web applications expose login interfaces that attackers probe continuously for weak credentials. The operational consequence: successful authentication often grants immediate access to email, file shares, and business applications across the organization.
Attackers harvest usernames through LinkedIn reconnaissance and email enumeration, building target lists using standard naming conventions like [email protected]. They test one password against the entire user base, wait 30 minutes to avoid lockout triggers, then cycle to the next common password. This timing pattern defeats traditional brute force protections designed to block rapid attempts against individual accounts.
Proxy Network Rotation
Attack campaigns rotate through residential IP pools and compromised machines to mask their geographic signatures. This distributed approach makes IP-based blocking ineffective and complicates forensic analysis. Attackers prioritize high-privilege accounts—administrators, service accounts, and executives—because these provide immediate lateral movement opportunities once compromised.
The business risk escalates when external authentication services lack geographic restrictions or device trust requirements. Attackers can probe from any location worldwide, testing credentials against cloud services that grant access to core business systems.
Business impact
Successful password spraying creates immediate business disruption through unauthorized access to critical systems and data exposure. When attackers compromise user accounts, they establish persistent access for lateral network movement and data exfiltration. Organizations face operational shutdown, regulatory violations, and customer notification requirements.
Financial consequences include incident response costs averaging $4.45 million per breach, regulatory fines under GDPR reaching 4% of annual revenue, and customer notification expenses. IT teams must force password resets across potentially affected accounts, creating productivity loss and overwhelming help desk resources.
Healthcare organizations face HIPAA violations when patient data gets accessed through compromised accounts. Financial services encounter regulatory scrutiny under SOX and banking regulations. The operational impact extends beyond initial compromise as business processes dependent on affected accounts face disruption until access gets restored through emergency procedures.
Detection guidance
Password spraying generates distinct authentication patterns that differ from normal user behavior and traditional brute force attacks. Multiple failed login attempts across many accounts from similar IP ranges indicate coordinated spray activity. The detection signature includes low-frequency failures per account but high volume across the user population.
Logic pattern / pseudocode — validate for your platform:
SELECT source_ip, COUNT(DISTINCT username) as unique_users,
COUNT(*) as total_attempts,
MIN(timestamp) as first_attempt,
MAX(timestamp) as last_attempt
FROM authentication_logs
WHERE result = 'FAILED'
AND timestamp >= NOW() - INTERVAL 24 HOURS
GROUP BY source_ip
HAVING unique_users >= 10
AND total_attempts >= 20
AND (last_attempt - first_attempt) >= INTERVAL 1 HOUR
ORDER BY unique_users DESC
Windows Event ID 4625 contains failed logon attempts with source IP and target username. Office 365 audit logs capture sign-in failures with geolocation data and user agent strings. VPN logs record authentication failures with timestamp precision needed for timing analysis.
Detection thresholds should start with 10 unique usernames from a single IP within 24 hours, then tune based on false positive rates. Note that the appropriate threshold depends on your environment size and normal authentication patterns — see MITRE ATT&CK T1110.003 for additional guidance. Look for attempts spaced 30-60 minutes apart, which indicates automated tooling designed to evade lockout policies.
Logic pattern / pseudocode — validate for your platform:
SELECT username, COUNT(*) as failure_count,
COUNT(DISTINCT source_ip) as unique_ips,
STDDEV(UNIX_TIMESTAMP(timestamp)) as timing_variance
FROM authentication_logs
WHERE result = 'FAILED'
AND timestamp >= NOW() - INTERVAL 6 HOURS
GROUP BY username
HAVING failure_count >= 3
AND unique_ips >= 2
AND timing_variance < 300
Monitor for successful authentications immediately following spray campaigns. Attackers often achieve some successful logins during the spray, then return to exploit those compromised accounts. Alert when any account that experienced recent authentication failures subsequently logs in from an unusual location or outside normal business hours.
Mitigation strategies
Multi-Factor Authentication Deployment
MFA blocks password spraying attacks even when attackers guess correct passwords by requiring additional verification factors. Deploy MFA for all external-facing applications and prioritize accounts with administrative privileges. The business tradeoff is user convenience versus complete elimination of credential-only attacks.
Even basic SMS-based MFA defeats password spraying campaigns because attackers cannot complete the second factor for compromised accounts. Hardware tokens and app-based authenticators provide stronger protection against more sophisticated attacks. Requiring additional verification for logins from unrecognized devices or unusual locations — a capability known as adaptive MFA — adds a further layer of defense; see Palo Alto Networks: What Is Adaptive MFA for a detailed overview.
Account Lockout Configuration
Configure lockout after 5 failed attempts within 30 minutes, with automatic unlock after 1 hour. This creates the primary technical barrier against spraying attempts while balancing legitimate user lockouts against attack mitigation. The operational consequence: help desk volume increases but attack success rates drop dramatically.
Progressive lockout policies extend protection by increasing lockout duration for repeated violations. Accounts that trigger multiple lockouts within 24 hours face extended restrictions, forcing attackers to abandon those targets or wait longer between attempts.
IP-Based Rate Limiting
Implement progressive delays that slow automated tools while minimizing impact on legitimate users: 1-second delay after 3 failures, 5-second delay after 5 failures, 30-second delay after 10 failures. This approach reduces spray effectiveness by making large-scale campaigns time-prohibitive.
Geographic restrictions block authentication attempts from countries where your organization doesn't operate. Conditional access policies require additional verification for logins from unrecognized devices or unusual locations, creating additional barriers for attackers using proxy networks.
Password Complexity Requirements
Enforce minimum 12-character passwords with complexity requirements and prohibit common passwords like "Password123!" or seasonal variations. Deploy password filters that block dictionary words and previously breached passwords. The implementation cost is user training and help desk support versus elimination of weak password vulnerabilities.
Regular password audits using breach databases identify accounts using compromised credentials before attackers discover them. Force immediate password changes for any accounts matching known breached passwords.
Getting started checklist
Immediate Actions (0-7 days):
- [ ] Enable authentication logging on all external-facing services
- [ ] Configure failed login attempt retention for minimum 90 days
- [ ] Deploy MFA on administrator accounts and external applications
- [ ] Review current account lockout policy settings
- [ ] Identify high-privilege accounts for priority protection
Short-term Implementation (1-4 weeks):
- [ ] Deploy SIEM detection rules for authentication failure patterns
- [ ] Configure IP-based rate limiting on web applications
- [ ] Implement automated alerting for spray attack signatures
- [ ] Create incident response playbook for detected spraying
- [ ] Establish baseline metrics for normal authentication patterns
Medium-term Hardening (1-3 months):
- [ ] Audit password policies across all systems
- [ ] Deploy conditional access controls based on geography and device
- [ ] Implement password breach monitoring and blocking
- [ ] Train security operations team on spray detection techniques
- [ ] Test incident response procedures with tabletop exercises
Ongoing Operations:
- [ ] Review authentication logs weekly for new attack patterns
- [ ] Tune detection thresholds based on false positive rates
- [ ] Update IP blocklists monthly with known malicious sources
- [ ] Assess MFA coverage quarterly and expand protection scope
- [ ] Monitor industry threat intelligence for new spray techniques
Sources
- MITRE ATT&CK T1110.003 — Password Spraying
- MITRE ATT&CK T1110 — Brute Force
- MITRE ATT&CK M1032 — Multi-factor Authentication
- MITRE ATT&CK M1027 — Password Policies
- MITRE ATT&CK M1036 — Account Use Policies
- Microsoft: Account Lockout Duration Policy
- Microsoft Entra Password Protection
- OWASP: Password Spraying Attack
- Palo Alto Networks: What Is Adaptive MFA

