Security Glossary

What is Password Spraying?

Password spraying tests a small set of common passwords against many usernames — the opposite of hammering one account. It stays under lockout thresholds while exploiting predictable passwords and exposed username formats.

How a Password Spraying Attack Works

1

Build a username list

Email formats from websites and LinkedIn make guessing trivial ([email protected]).

2

Pick common passwords

Seasonal passwords and company-related strings are tried slowly across the directory.

3

Authenticate where MFA is weak

Legacy protocols or excluded accounts often lack strong MFA.

4

Expand access

A single mailbox or VPN login becomes the pivot for broader compromise.

Real-World Example

A university's staff email pattern was published in a style guide PDF. Attackers sprayed SeasonYear! across hundreds of accounts overnight and hit several without MFA on legacy IMAP.

How AiVERSARY Detects Password Spraying Risk

AiVersary identifies how easily outsiders can infer email and naming patterns from public sources — the raw material for spraying and stuffing campaigns.

Is your organization exposed to password spraying?

AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.

Get Your Threat Report

Related Terms

Credential Stuffing

Credential stuffing is when attackers take usernames and passwords leaked from one breach and automatically try them on other services. Because most people reuse passwords, a breach at a shopping site or social network can give attackers working credentials for your corporate email, VPN, or cloud platforms. It is automated, fast, and alarmingly effective.

MFA Fatigue

MFA fatigue is an attack where a criminal who already has your password repeatedly triggers multi-factor authentication prompts — the push notifications on your phone — until you approve one just to make them stop. It exploits the very security measure designed to protect you by turning it into an annoyance that people instinctively dismiss. This technique has been used in several high-profile breaches.

Tenant Compromise

Tenant compromise is when an attacker gains administrative control over your organization's cloud environment — your Microsoft 365 tenant, Google Workspace, or AWS account. Unlike stealing a single employee's password, this gives the attacker the keys to everything: every email, every file, every application, and every user account in your cloud infrastructure. It is the most devastating outcome of a successful credential attack.

OSINT Reconnaissance

OSINT reconnaissance — Open Source Intelligence gathering — is the first phase of nearly every targeted cyberattack. It's the process of collecting publicly available information about an organization and its people to plan an attack. Everything from your company website and LinkedIn profiles to job postings, DNS records, and conference presentations becomes intelligence. This is exactly the same process AiVersary uses, but we do it first so you can fix what's exposed.