Skip to main content
Attacks and Threats

Password Spraying

A type of brute force attack where a small set of commonly used passwords are tried across many accounts to avoid triggering account lockout thresholds.

Password spraying is a brute force variant that inverts the typical approach. Instead of trying many passwords against one account (which triggers lockouts), the attacker tries a few common passwords (like “Password123!” or “Summer2024!”) against many accounts.

By keeping attempts per account below the lockout threshold, password spraying often evades detection. It’s particularly effective against organizations with weak password policies or that don’t use MFA.

The defense is straightforward: enforce unique, randomly generated passwords for all accounts (eliminating common passwords from the organization), implement MFA, and monitor for distributed login failures across multiple accounts, a telltale sign of password spraying.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide