Press ESC to close or Enter to search

Home
About Us
Services
Pricing
Tools
Resources
Contact
Get Started
Live Security Feed
Your IPDetecting...
NCSCUK organisations urged to strengthen cyber defences ALERTPhishing attacks targeting Microsoft 365 users on the rise CISACritical vulnerabilities identified in popular software NEWSRansomware groups increasingly targeting SME businesses NCSCNew guidance released for securing remote workers ALERTBusiness email compromise attacks cost UK firms millions CISAZero-day exploits require immediate patching attention NEWSAI-powered threats becoming more sophisticated in 2025 NCSCUK organisations urged to strengthen cyber defences ALERTPhishing attacks targeting Microsoft 365 users on the rise CISACritical vulnerabilities identified in popular software NEWSRansomware groups increasingly targeting SME businesses NCSCNew guidance released for securing remote workers ALERTBusiness email compromise attacks cost UK firms millions CISAZero-day exploits require immediate patching attention NEWSAI-powered threats becoming more sophisticated in 2025
View Dashboard

Password Spraying

Attacks

Attack that tries a few common passwords against many accounts to avoid triggering lockouts.

Password spraying reverses the typical brute force approach—instead of trying many passwords against one account, it tries a few common passwords against many accounts. This avoids account lockout thresholds while exploiting the statistical likelihood that some users have weak passwords. Attackers test passwords like 'Summer2024!' or 'CompanyName1' across all discoverable accounts. A single success provides access. Password spraying is particularly effective against organisations without MFA.

Why It Matters

The DSC Perspective:

Password spraying defeats account lockout policies. Even with lockouts configured, if any user has a weak password, attackers get in. Strong password policies, banned password lists, and MFA are essential defences.