Start with Identity
← Glossary
Threat

Password Spraying

Trying a few common passwords across many accounts to avoid lockouts. Effective against weak password policies and accounts without MFA.

Spraying is designed to stay under lockout thresholds, so per-account controls do not see it and only population-level detection does: a small number of failures across a large number of accounts from a narrow set of sources. It remains effective because a predictable seasonal password still works somewhere in any organization above a few thousand people. Banning common and breached passwords does more than complexity rules.

See also: credential stuffing, account takeover, MFA, what is ITDR

Last reviewed By SWI Community TeamSuggest a correctionHow we research