CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Password spraying attacks surge 155x as hackers exploit MFA gaps

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4691

As cited

Copy frozen at (site build).

threat intel

Password spraying attacks surge 155x as hackers exploit MFA gaps

Huntress reported a 155-fold increase in password spraying attacks during the first half of 2026, with one campaign alone generating over 81 million login attempts within two weeks. The attacks exploited legacy authentication systems and gaps in multi-factor authentication (MFA) policies that left certain login flows unprotected.

Why it matters: Security teams managing authentication systems should audit MFA coverage and legacy authentication endpoints to block password spraying campaigns that continue to escalate in volume.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Password spraying attacks surge 155x as hackers exploit MFA gaps

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Password spraying attacks surge 155x as hackers exploit MFA gaps

Huntress documented a 155-fold surge in password spraying attacks during the first half of 2026, with one campaign executing over 81 million login attempts in two weeks. The attacks targeted legacy authentication systems and gaps in multifactor authentication (MFA) policies that left certain login flows undefended.

Why it matters: Organizations using legacy authentication or incomplete MFA coverage face immediate exposure to account compromise; practitioners should audit MFA enforcement across all login paths and disable older authentication protocols.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary