# 81 Million Login Attempts in Two Weeks: The Password Spray Surge That MFA Didn't Stop
The number that should stop security teams cold isn't 155. It's 81 million.
That's how many login attempts a single password spraying campaign generated in fourteen days, according to threat intelligence firm Huntress. And if your first instinct is to think "fine, we have MFA" — that's exactly the assumption attackers are counting on.
Huntress tracked a 155-fold increase in password spraying activity across the first half of 2026. Not a modest uptick. Not a seasonal blip. A 155x surge in a class of attack that most organizations stopped worrying about years ago, once they checked the MFA box and moved on.
That box was never as complete as they thought.
## The Gap That 155x Proves
Password spraying works differently than brute-force attacks. Instead of hammering one account with thousands of guesses, attackers try one or two common passwords — "Spring2026!" is perennial — against thousands of accounts. Slow enough to avoid account lockout policies. Distributed enough to dodge rate limiting. Methodical enough to find the one account where someone reused their leaked LinkedIn password.
The reason MFA doesn't automatically neutralize this is specific: legacy authentication protocols. Exchange ActiveSync. IMAP. SMTP AUTH. Basic Auth over Exchange Web Services. These protocols — many of them decades old — don't support modern authentication flows. When a user connects a mail client, a mobile device, or a third-party integration through one of these pathways, the request bypasses the MFA prompt entirely.
Organizations that deployed MFA on their primary login portals — the shiny SSO page, the Entra ID or Okta flow — often left these side doors wide open. Attackers know this. They specifically hunt for tenants where legacy auth hasn't been disabled, where Conditional Access policies have exceptions, where some service account gets a carve-out because someone in IT didn't want to deal with the change management.
The 81 million attempts in two weeks wasn't a lottery play. That was a systematic sweep through exactly those gaps.
## Why 2026 Is Different
Password spraying isn't new. Microsoft was screaming about legacy authentication abuse in 2019. CISA flagged it. The whole security community flagged it. And yet here we are.
The scale change in H1 2026 has a few likely drivers. First, the volume of compromised credential lists has expanded enormously — the aggregation of breach data means attackers have increasingly accurate, recently-validated password sets to spray with. "One common password across thousands of accounts" is actually a conservative framing when attackers also have target-specific guesses built from previous breaches at the same company or sector.
Second, cloud migration has changed the attack surface geometry. Legacy auth protocols didn't disappear when companies moved to Microsoft 365 or Google Workspace — they migrated with the tenant. Organizations running hybrid environments, or those that moved cloud-fast without a thorough security review, are particularly exposed. The bigger the Microsoft 365 deployment, the more likely some service account, some shared mailbox, some integration from three acquisitions ago is still authenticating via Basic Auth.
Third, automation tooling for these campaigns is genuinely sophisticated now. The 81 million attempt campaign wasn't someone manually cycling through passwords. These are coordinated, distributed operations that spoof user agents, rotate IPs through residential proxy networks, and time their attempts to match normal business hour traffic patterns.
## What Defenders Actually Need to Do
The Huntress data is a useful forcing function to revisit assumptions that solidified years ago. Three places to start:
Audit your legacy authentication exposure first. In Entra ID (Azure AD), the Sign-in logs will show you every authentication event broken down by client app. Filter for Exchange ActiveSync, IMAP, POP3, SMTP, and Authenticated SMTP. The volume and the accounts hitting those pathways will tell you exactly what's still exposed. If you haven't disabled Basic Auth completely, you have exposure.
Treat Conditional Access policy exceptions as debt. Every exception — "except for service accounts," "except for this integration," "except for this executive's iPad" — is a potential attack pathway. Map them. Most of them exist because disabling legacy auth broke something and the fix was an exception instead of remediation. Go back and do the remediation.
Look specifically at your service accounts and shared mailboxes. These are the accounts least likely to have proper MFA enrolled, most likely to use legacy auth, and most likely to have permissions far beyond their nominal purpose. In a tenant with 500 users, there are probably 30-50 of these accounts. Attackers focus there because a successful spray against a service account often gives them persistent, low-profile access.
Enable sign-in risk policies. Modern identity platforms can detect anomalous login behavior — unusual location, impossible travel, unfamiliar device fingerprints. These detections are only useful if they trigger a block or a step-up challenge rather than just generating an alert no one reads.
---
## HackWire Analysis
The 155x increase figure will dominate the headlines, but the more important number is how many of those campaigns actually succeeded — which Huntress doesn't fully disclose in their summary, and which almost no organization is equipped to measure accurately.
That's the real problem this data surfaces. Most companies don't have the logging fidelity or the SIEM queries to know whether they've already been hit by one of these campaigns. A successful password spray that authenticates via legacy auth and doesn't trigger an MFA challenge may generate nothing more than a normal-looking sign-in event. Unless someone is specifically hunting for impossible travel, unfamiliar ASNs, or anomalous mail client signatures in their identity logs, the attacker is already inside.
This fits a pattern that's been building for three years: attackers have internalized that the primary login flows are increasingly well-defended, so they are systematically routing around them. OAuth consent phishing does the same thing. Adversary-in-the-middle kits like Evilginx2 capture session tokens post-MFA. Password spraying via legacy auth is the oldest version of this same playbook.
The implication for defenders is uncomfortable. MFA was treated as a finish line, and it isn't one. The attack surface for credential abuse is still broad, and it runs through every authentication pathway that isn't the main SSO flow. The orgs that will weather the next 155x surge are the ones that have already done the unglamorous work — disabled legacy auth, eliminated Conditional Access exceptions, and built detection for the specific behavioral signatures of spray campaigns. Everyone else is relying on their attackers being unlucky.
— HackWire Editorial
---
## Related Coverage