What Is Password Spraying and How Does It Work?
Blog post from Ory
Password spraying is a low-and-slow brute-force technique in which attackers test a few common passwords across many accounts, avoiding per-account lockout thresholds and making detection difficult without organization-wide log correlation. Attackers often collect usernames through public sources or breach data, distribute attempts across proxies and IP addresses, target high-value SSO portals, VPNs, and legacy protocols such as IMAP, POP3, and SMTP that may bypass MFA, then use successful logins for lateral movement and privilege escalation. It differs from conventional brute force, which makes many guesses against one account, and credential stuffing, which reuses previously breached credential pairs. Recommended defenses include eliminating common and compromised passwords, enforcing phishing-resistant MFA or passkeys, disabling or restricting legacy authentication, applying risk-based authentication and cross-account rate limits, and monitoring authentication activity through centralized correlation tools. Incident response should contain malicious traffic, reset affected credentials, investigate post-login activity, and address the authentication gaps that enabled the attack, while passwordless methods such as passkeys are presented as the most direct way to remove passwords from the attack surface.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 3 | 931 | 231 | 103 | -84% |
| Observability | 1 | 472 | 102 | 54 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.