Password Spray Attacks: How One Slow-Motion Guess Slips Past Lockout Policies

Ulises Paiz

Ulises Paiz, Founder of Ghosxt, has 10+ years in IT infrastructure and cybersecurity, deep DoD infrastructure experience, and 9 certifications including CySA+, Security+, and AZ-104. Before founding Ghosxt, he served as a Senior Solutions Consultant for the DoD and built security programs for 40+ Central Coast businesses. More about Ulises →

Most small business owners picture password attacks as a brute-force problem: a computer somewhere trying millions of combinations against one login page until it either gets locked out or gets lucky. That mental model is exactly why account lockout policies exist, and it's exactly what password spraying is built to avoid. Instead of guessing hard against one target, the attacker guesses easy against everyone. One password, tried once against every employee email address the company has, then a second password, then a third: slow, quiet, and invisible to any system that only watches for repeated failures on a single account.

Why the math favors the attacker

A single guess against a single account is a bad bet for an attacker; most passwords aren't "Password1" or "Summer2026!" But a single common password tried against 200 employee accounts is a much better bet, because it only takes one person out of 200 to have picked a weak or seasonal password for the attack to succeed. Small businesses are frequently more exposed here than larger ones, not less: a 15-person company might have every login exposed on a single Microsoft 365 or Google Workspace tenant, and if the password policy allows something like "Ghosxt2026!" to pass complexity checks, there's a real chance at least one employee is using a close variant of it. Attackers know this, and password-spray tooling is built to try exactly the kind of seasonal, company-name, or keyboard-pattern passwords people default to when a policy forces a "complex" password but doesn't ban common ones.

The blind spot lockout policies were never built for

Account lockout after a handful of failed logins is one of the oldest, most reliable password controls there is, and it does exactly what it was designed to do: stop someone from repeatedly guessing against one account. Password spraying doesn't fight that control, it routes around it entirely by never repeating an attempt on the same account often enough to trigger it. An attacker might try one password against every account in the company, wait an hour or a day, then try the next password. From the perspective of any one employee's account, that looks like a single incorrect password entry, the kind everyone types by accident occasionally. The pattern only becomes visible when someone is looking across the whole tenant at once: a spike in failed logins spread across dozens of different usernames in a short window, rather than concentrated on one.

  • Cloud logins are the main target. Microsoft 365, Google Workspace, and VPN portals are internet-facing by design, which is exactly what makes them reachable for this kind of low-and-slow attempt.
  • Shared or predictable naming conventions help the attacker. If every employee's login is firstname.lastname@company.com, the attacker doesn't even need to guess usernames, only passwords.
  • Seasonal password policies backfire. A policy that nudges people to reset to "Season+Year+Symbol" every quarter makes the exact pattern attackers try first.

What actually closes the gap

Multi-factor authentication is the single control that matters most here, because it changes what a correct password guess is worth. If an attacker sprays the right password against the right account, but a phone approval, authenticator code, or hardware key is still required, the guess alone doesn't get them in. Beyond MFA, banning known weak and previously breached passwords at the policy level (Microsoft Entra and Google Workspace both support this natively) removes the exact low-hanging passwords spray tools try first. Sign-in risk policies that flag or block logins from unexpected countries or impossible-travel patterns catch a lot of spray attempts, since the login attempts rarely originate from where employees actually are. And centralized monitoring that looks at failed-login volume across the whole organization, not per account, is what actually surfaces a spray campaign while it's happening instead of after an account is compromised.

Where this fits

  • The credential stuffing post, for the related attack that uses already-breached password lists instead of common guesses.
  • The MFA fatigue post, for what an attacker tries next once they have a working password and MFA is the only thing left in the way.
  • The passkeys post, for removing guessable passwords from the login flow entirely.
  • The dark web monitoring post, for knowing when your company's credentials show up somewhere an attacker could use them.

FAQs about password spray attacks

What is a password spray attack?

A password spray attack tries one commonly used password, like Summer2026! or Password1, against many different usernames at the same company before moving on to the next password. Because each account only sees one or two login attempts, the attack avoids the failed-login threshold that would normally lock an account or raise an alert.

How is password spraying different from brute force or credential stuffing?

Brute force throws many passwords at one account until a lockout policy stops it. Credential stuffing replays already-breached username-and-password pairs against a login page, hoping for reuse. Password spraying tries one password across many accounts at once, staying under the failed-attempt threshold for every individual account it touches.

Does an account lockout policy stop password spraying?

Not by itself. A lockout policy triggers after several failed attempts on the same account, but password spraying deliberately keeps each account's failed-attempt count low by rotating through the whole user list instead of repeating one account. The attack is built specifically around that blind spot.

What actually stops password spray attacks?

Multi-factor authentication is the single most effective control, since a correctly guessed password still isn't enough to log in. Beyond that: banning commonly used and previously breached passwords at the password policy level, geographic and impossible-travel sign-in restrictions, and alerting on a spike in failed logins across many different accounts rather than just one.

Not sure if your logins would survive a password spray?

30 minutes with an engineer with DoD infrastructure experience. We'll review your MFA coverage, password policy, and sign-in monitoring, and show you exactly where a low-and-slow attack would get through today.

Book your free security assessment
Call (831) 204-0501 Book free assessment