Brute force is loud. Hammer one account with a million guesses and any competent login system will lock it, throttle it and page someone. So attackers who work at scale mostly don't do that. They do the opposite: they take one boring password - Password123, Summer2026!, Welcome1 - And try it once against ten thousand accounts. Then they wait a few hours and try the next one.
That's password spraying. It's slower than brute force, far less glamorous, and responsible for some of the most consequential intrusions of the past decade - Including the one that reached the inboxes of Microsoft's own senior leadership in 2024. It works because in any sufficiently large group of people, someone is always using the password the attacker guessed.
The attack, mechanically
A spray needs three ingredients, and none of them is sophisticated.
A list of usernames. For companies, email addresses follow guessable formats (first.last@company.com) and can be scraped from LinkedIn, marketing sites and old breach dumps. For consumer services, breach data supplies usernames by the hundreds of millions.
A short list of candidate passwords. Not a cracking dictionary - A curated top-20. Defaults like Welcome1, keyboard walks like Qwerty123!, and above all formula passwords: season plus year, company name plus year, month plus punctuation. These are the passwords people invent when a policy forces a change and they need something that passes complexity rules. Our roundup of the most common passwords shows how depressingly predictable those choices are.
Patience. The attacker tries password #1 against every account on the list, spread across hours and rotated through proxy IPs. One failed login per account per day looks like a user's typo, not an attack. Then password #2. A campaign might run for weeks.
The economics are the point. The attacker doesn't care about your account. They care that, statistically, some fraction of any org's users chose Autumn2026! - And one valid login into a corporate email tenant, VPN or SSO portal is a foothold worth real money.
Why the lockout alarm never rings
Almost every defense built for password guessing watches one signal: repeated failures on a single account. Lock after five bad tries, alert after ten. Spraying is engineered to stay invisible to exactly that signal.
| Brute force | Credential stuffing | Password spraying | |
|---|---|---|---|
| Guesses per account | Thousands to billions | One (the leaked pair) | One to a handful |
| Accounts targeted | One | Millions | Hundreds to thousands |
| What it exploits | Weak/short passwords | Password reuse | Common password choices |
| Trips account lockout? | Yes, immediately | Rarely | Almost never |
| Best defense | Length and randomness | Unique passwords per site | No guessable passwords + MFA |
Spraying's siblings each have their own logic. Credential stuffing replays passwords the attacker already knows from breaches; spraying guesses passwords nobody leaked, betting on human predictability. Classic dictionary attacks run huge wordlists against stolen password hashes offline; spraying works online, against the live login page, where each guess is expensive - Which is precisely why it spends its few guesses on the likeliest candidates.
Detection is possible, but it requires looking at the tenant-wide picture: a slow rise in failed logins spread thinly across many accounts, from unfamiliar IP ranges. Most small organizations never look at that view.
A brute-force attack asks "what is this user's password?" A spray asks "which of these users has this password?" - And in any large group, the answer is never "none of them."
Real intrusions that started with a spray
This is not a theoretical technique. In January 2024, Microsoft disclosed that Midnight Blizzard - The Russian state-sponsored group also tracked as APT29 - Had accessed corporate email accounts belonging to members of its senior leadership and security teams. The initial entry point, per Microsoft's own incident report, was a password spray against a legacy, non-production test tenant account that lacked multi-factor authentication. One forgotten account, one guessable password, and a patient adversary.
Years earlier, the FBI advised Citrix that the attackers who breached its internal network in 2019 likely got in the same way. And CISA and the NSA have issued repeated advisories attributing long-running spray campaigns against cloud services, defense contractors and critical infrastructure to state-backed groups from Russia and Iran. The technique persists because the target - Human password-choosing habits - Regenerates every time a password policy forces a reset.
What sprayers guess first
Spray lists are short, so they're ruthlessly optimized. Recurring themes:
- Season + year + symbol:
Summer2026!,Winter26!- Compliant with nearly every complexity policy, reinvented daily by users forced to rotate passwords. - Company or brand + year:
Contoso2026,Acme@2026- Especially effective against the company in question. - Fresh-start defaults:
Welcome1,Changeme123!,Password1!- Common where IT provisions accounts and users never change them. - Local flavor: sports teams, city names, the current month.
Notice that every one of these sails past "must contain an uppercase letter, a number and a symbol." Composition rules don't stop sprays; they shape them, by pushing everyone toward the same handful of compliant patterns. This is a core reason NIST's SP 800-63B guidance dropped mandatory composition rules and periodic forced resets in favor of screening passwords against blocklists of common and breached choices.
How to make spraying fail
The defense is unusually clean, because spraying only ever guesses popular passwords.
Use a random password. A spray list has, at most, a few hundred entries. A randomly generated 16-character password will never appear on it - Not "probably won't," won't. If you're unsure whether your current password is formula-shaped, run it through a password strength checker and be honest about how you'd rebuild it from memory; if the recipe is "word + year + punctuation," a sprayer has already tried it.
Turn on multi-factor authentication. Every headline spray intrusion, Microsoft's included, ran through an account without MFA. A TOTP code from an authenticator app - You can see exactly how those six-digit codes are derived with our TOTP generator - Turns a correct password guess into a failed login. Microsoft has said for years that MFA blocks over 99% of automated account-compromise attempts, and sprays are the definition of automated.
For organizations: blocklist and monitor. Screen new passwords against common-password and breached-password lists at creation time, alert on tenant-wide failed-login patterns rather than per-account counts, and hunt down legacy accounts and protocols that skip MFA - That's where sprays land. Our guide to password policy best practices covers the NIST-aligned setup in detail.
FAQ
Is password spraying illegal?
Yes. Attempting to log in to accounts you don't own is unauthorized access under computer-crime laws in essentially every jurisdiction - The US CFAA, the UK Computer Misuse Act and their equivalents. The "low and slow" pacing changes detection odds, not legality.
How is spraying different from credential stuffing?
Stuffing replays real email-password pairs leaked in breaches, so it only works against people who reuse passwords. Spraying guesses common passwords against accounts whose passwords never leaked, so it works against people who choose predictable passwords. Unique passwords defeat stuffing; unpredictable passwords defeat spraying. A password manager delivers both properties at once.
Would an account lockout policy protect me?
Only partially. Lockouts trigger on repeated failures against one account, and sprays deliberately stay below that threshold - Often one guess per account per day. Lockouts remain worth having because they stop classic brute force, but against spraying the real defenses are unguessable passwords and MFA.
Are individuals targeted, or just companies?
Both. Corporate SSO portals, VPNs and email tenants are the high-value targets, but consumer services get sprayed constantly too - Streaming, gaming and retail accounts are resold in bulk. If your password for any service is a dictionary word plus a year, you're inside somebody's spray list right now.
My password is a common one with a few letters swapped. Am I safe?
No. Spray lists include the standard substitutions - P@ssw0rd1, Summ3r2026! - Because attackers know the same tricks users do. Swaps that feel clever are among the first variants tried. The only reliable escape is a password with no recipe at all: randomly generated and stored in a manager.