Password spraying spikes 155x as MFA gaps leave some flows unprotected
Source headline: Password spraying attacks surge 155x as hackers exploit MFA gaps
Intelligence Summary
Huntress reports a 155x increase in password spraying attacks in H1 2026. One campaign generated more than 81 million login attempts over two weeks. The activity targeted legacy authentication paths. It also exploited gaps in MFA policies that left some login flows unprotected. The risk is account takeover attempts against organizations with incomplete MFA coverage. Review authentication and MFA coverage for all login flows and block or limit password spraying attempts.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.