Attack technique

Password Spraying

An attack that tries a small number of common passwords against a large number of accounts, one password at a time, to avoid triggering account lockout policies.

Definition

Password spraying is an attack technique in which an attacker tries one or a small handful of commonly used passwords, such as a season and year or a company name variant, against a large number of different user accounts before moving on to the next password. By spreading attempts across many accounts instead of repeatedly guessing at a single one, the attacker stays under most account-lockout thresholds while still relying on the statistical certainty that some fraction of any large user base is using a weak, guessable password.

Traditional brute-force attacks focus all their guesses on one account, which quickly triggers a lockout policy after a handful of failed attempts. Password spraying inverts this: the attacker picks a shortlist of highly common passwords, often sourced from breach analysis of the most frequently reused passwords, and tries just one or two against every account in an organization's directory before waiting and trying the next password. Because each individual account only sees one or two failed attempts, the activity rarely crosses a lockout threshold and can be spread over hours or days to further avoid detection.

This technique is particularly effective against large organizations with predictable username formats, such as first-name.last-name email addresses, since attackers can enumerate a huge target list from a single company domain and public sources like LinkedIn. Password spraying is a common precursor to account takeover and has been used against corporate VPNs, webmail, and single sign-on portals at Indonesian banks and government agencies, precisely because a single successful guess against an employee with elevated access can be enormously damaging.

The defense that matters most is eliminating weak, common passwords in the first place through a strong password policy or, better, multi-factor authentication that renders a correctly guessed password insufficient on its own. Monitoring for a pattern of low-and-slow failed logins spread across many accounts, rather than repeated failures on one account, is essential for detection, since traditional lockout-based alerting is specifically designed to miss this technique. Banning known weak and breached passwords at the point of password creation closes off the pool of guesses an attacker can spray in the first place.

At a glance

Severity
Medium
Prevalence
Common
Primary targets
Corporate VPN, webmail, and SSO login portals
Also known as
Low-and-slow password attack

How it works

  1. 1

    Target enumeration: the attacker builds a list of valid usernames for an organization, often from a predictable email format and public sources like LinkedIn.

  2. 2

    Password shortlist: a small set of commonly used passwords is chosen, based on known weak-password patterns such as a season, year, or company name.

  3. 3

    Low-volume attempts: only one or two passwords are tried against each account before moving to the next, keeping failed attempts per account below lockout thresholds.

  4. 4

    Spread over time: attempts are paced over hours or days across the entire account list to avoid triggering rate-based alerts.

  5. 5

    Success on weak accounts: the statistical odds mean at least a few accounts in any large directory are using one of the sprayed passwords.

  6. 6

    Access and escalation: a successful login is used for further reconnaissance, data theft, or as a foothold toward account takeover.

Warning signs

  • A wave of failed login attempts spread across many different accounts rather than repeated failures on one
  • Login attempts against dormant, service, or shared accounts that are rarely used interactively
  • Sign-ins using common or seasonal passwords flagged by password-policy screening
  • Authentication attempts arriving from a small number of IP addresses against a broad set of usernames
  • A successful login immediately followed by unusual access to systems that account does not normally use

How to defend

  • Enforce multi-factor authentication on all corporate accounts, especially VPN, webmail, and SSO
  • Ban known weak and breached passwords at the point of password creation, not just complexity rules
  • Monitor authentication logs for low-and-slow failed-login patterns spread across many accounts
  • Set conservative lockout and throttling policies that also account for spray-style attempts, not only repeated single-account failures
  • Avoid predictable username formats where feasible, or add compensating monitoring where they cannot be changed
  • Run regular password audits to find and force resets of common or previously breached passwords

Real-world example

An attacker targets a government agency's single sign-on portal, guessing that some staff still use a password based on the current year and the agency's name. Rather than repeatedly guessing against one account and triggering a lockout, the attacker tries this single password against every username in the agency's predictable email format, quietly finding three accounts where it works before moving on to internal systems.

How Claro helps

Claro's risk scoring and security awareness modules highlight departments and roles still relying on weak or predictable passwords, giving Indonesian tenants a data-backed case for enforcing stronger password policies and multi-factor authentication before an attacker finds the weak account first.

Frequently asked questions

How is password spraying different from brute force?

Brute force repeatedly guesses many passwords against one account, which quickly triggers lockout policies. Password spraying tries only one or two passwords across many accounts, staying under lockout thresholds while still finding accounts with weak passwords.

Why don't account lockout policies stop password spraying?

Lockout policies are typically triggered by repeated failures on a single account. Since password spraying only makes one or two attempts per account before moving to the next, it rarely accumulates enough failures on any one account to trigger a lockout.

Does multi-factor authentication stop password spraying?

Yes, in nearly all cases. Even if the sprayed password matches, the attacker still needs the second authentication factor, which they do not have.

Who is most at risk from password spraying?

Large organizations with predictable username formats and any account still using a common, seasonal, or company-name-based password are the most exposed, since attackers can enumerate the target list easily and rely on statistical odds across many accounts.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo