← Back to Feed
Password spraying attacks surge 155x as hackers exploit MFA gaps
August 19, 2026 · BleepingComputer · Severity: HIGH
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected.
Key Takeaways
- Huntress observed a massive 155x increase in password spraying attacks during the first half of 2026 compared to previous periods.
- One single campaign generated more than 81 million login attempts in just two weeks against targeted organizations.
- The attacks leveraged legacy authentication protocols and gaps in multi-factor authentication policies to bypass security controls.