CIO Brief: Password Spraying Is Cheap for Attackers — Is Your Tenant Ready?
Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.
The short version: In 2018, the US indicted Iranian hackers who stole large volumes of data by trying common passwords against thousands of accounts. It is a cheap attack that still works against organizations that allow weak passwords or older sign-in methods.
Why password spraying keeps working
Attackers don't need to guess everyone's password — just one. In a company of a few hundred people, someone is likely using a predictable password like a season and year. If any sign-in method doesn't require a second factor, that one password is enough.
The business impact
- Mailbox compromise leading to invoice fraud and data theft.
- A foothold for larger attacks.
- Low cost for attackers, so it is attempted constantly.
Questions to ask your team
- Have we blocked older sign-in methods that skip multi-factor authentication?
- Do we prevent people from choosing common or company-related passwords?
- Is MFA enforced for every account, including shared and service accounts?
- Would we see a spraying attack in progress?
What good looks like
Legacy sign-in methods blocked, weak passwords banned, MFA everywhere, and alerts when many accounts see failed sign-ins from the same source.
The decision
Ask your team to confirm in writing that legacy authentication is blocked across your Microsoft 365 tenant. If the answer is "mostly," close the gap this month.
- The Mabna Institute Indictment (Mar 2018): Password Spraying Against Cloud Email Incident Teardowns
- How to Block Legacy Authentication to Stop Password Spraying in Microsoft 365 How-To & Hardening
- Detecting Password Spraying: Defender XDR and Sentinel Hunting Queries Detection & Response