IAMRoadmapIAMRoadmap
INDUSTRY TRENDS

IAM News: Password spraying attacks surge 155x as hackers exploit MFA gaps

Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks.

2 min readAugust 19, 2026IAM Roadmap Team

Key Insight

Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in ...

📰 Source: Bleeping Computer

Summary

Password spraying attacks have surged 155x in the first half of 2026, with a notable campaign generating over 81 million login attempts in two weeks. These attacks exploited legacy authentication and gaps in multi-factor authentication (MFA) policies. As a result, many organizations are left vulnerable to these types of attacks.

Attack Flow

Password List Gathering

Password Spraying

Authentication Success

Data Exfiltration

Attacker

Legacy Authentication

Unprotected Login Flow

Access Granted

Target System

IAM Impact

The surge in password spraying attacks highlights the importance of a robust identity and access management (IAM) strategy. Organizations with outdated authentication protocols and incomplete MFA configurations are particularly vulnerable to these types of attacks. As a result, IAM practitioners must prioritize the implementation of modern authentication protocols and ensure that all login flows are properly secured with MFA.

Key Takeaways

  • Legacy Authentication Risks: Outdated authentication protocols are a major target for password spraying attacks.
  • MFA Gaps: Incomplete or improperly configured MFA policies leave organizations vulnerable to these types of attacks.
  • Continuous Monitoring: Regularly monitor login attempts and authentication protocols to identify potential vulnerabilities.

Recommendations

  • Implement Modern Authentication Protocols: Replace legacy authentication protocols with modern, more secure alternatives.
  • Ensure Complete MFA Coverage: Verify that all login flows are properly secured with MFA, including legacy authentication protocols.
  • Regularly Monitor and Analyze Login Attempts: Implement continuous monitoring to identify potential vulnerabilities and detect password spraying attacks.
Trend Topics
IAM newssecurity newsBleeping Computer
All Articles