Password spraying attacks surge 155x in H1 2026, exploiting MFA gaps
Huntress telemetry reveals campaign generating 81 million login attempts in two weeks

Key Takeaways
- Password spraying attacks increased 155x in H1 2026 according to Huntress telemetry.
- One campaign generated over 81 million login attempts in two weeks.
- Attacks exploited legacy authentication and gaps in MFA policies.
- Some login flows remained unprotected, enabling the spraying campaigns.
- Organizations should enforce strong MFA policies and disable legacy authentication where possible.
Quick answers
- What happened?
- Huntress researchers observed a 155-fold increase in password spraying attacks during the first half of 2026. One campaign generated over 81 million login attempts within a two-week period, exploiting legacy authentication protocols and gaps in multi-factor authentication policies that left certain login flows unprotected.
- What should defenders do?
- Implement strong MFA policies across all authentication flows; disable legacy authentication where possible; enforce per-user MFA requirements; monitor for unusual login patterns; implement rate limiting and account lockout policies.
According to Huntress telemetry, password spraying attacks increased by 155 times in the first half of 2026 compared to previous periods. A notable campaign generated more than 81 million login attempts over a two-week span. The attacks targeted organizations relying on legacy authentication methods and exploited inconsistencies in multi-factor authentication implementation. Some login flows remained unprotected, allowing threat actors to conduct password spraying with reduced risk of detection. The findings highlight the continued risk posed by credential-based attacks when MFA is not uniformly enforced across all authentication pathways. Huntress reported that the volume of attempts was significant enough to warrant attention from security teams, particularly those managing hybrid environments with legacy systems.
Security Details
Password spraying attacks targeted legacy authentication systems and exploited inconsistencies in multi-factor authentication policies. Some login flows were unprotected, allowing threat actors to conduct high-volume login attempts to evade detection.
Mitigation
Implement strong MFA policies across all authentication flows; disable legacy authentication where possible; enforce per-user MFA requirements; monitor for unusual login patterns; implement rate limiting and account lockout policies.
Sources
BleepingComputer
Password spraying attacks surge 155x as hackers exploit MFA gaps
Aug 19, 2026 · 14:00
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




