← Back to Feed

Password spraying attacks surge 155x as hackers exploit MFA gaps

August 19, 2026 · BleepingComputer · Severity: HIGH

Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected.

Key Takeaways

  • Huntress observed a massive 155x increase in password spraying attacks during the first half of 2026 compared to previous periods.
  • One single campaign generated more than 81 million login attempts in just two weeks against targeted organizations.
  • The attacks leveraged legacy authentication protocols and gaps in multi-factor authentication policies to bypass security controls.
☕ Buy a Coffee