Cyber

Password Spraying Attacks Surge 155x Amid MFA Gaps

Huntress observed a massive 155x increase in password spraying attacks driven by legacy auth and MFA vulnerabilities.

·1 min read
Password Spraying Attacks Surge 155x Amid MFA Gaps

Security researchers at Huntress have reported a staggering 155x increase in password spraying attacks during the first half of 2026. This massive surge highlights how threat actors are aggressively exploiting weaknesses in corporate perimeter defenses.

The attacks primarily leveraged legacy authentication methods and gaps in multi-factor authentication (MFA) policies that left critical login flows unprotected. By targeting these blind spots, attackers were able to bypass standard security controls without triggering immediate alarms.

In one notable campaign observed by the researchers, hackers generated more than 81 million login attempts within a span of just two weeks. Such automated and high-volume operations demonstrate the scale and persistence of modern cybercriminal syndicates.

This trend serves as a critical warning for organizations and IT professionals globally, including emerging tech markets. Companies must immediately audit their authentication pipelines, phase out legacy protocols, and ensure universal MFA enforcement across all access points.

Cybersecurity experts strongly advise continuous monitoring, strict policy enforcement, and proactive vulnerability assessments to defend against these sophisticated automated threats before they result in major breaches.

#Kiberxavfsizlik#MFA#Parol purkash#Hackerlik#IT xavfsizlik#BleepingComputer

Related articles