Password spraying

An online guessing attack that tries a few common passwords against many accounts, keeping each account below its lockout threshold so per-account defences are not triggered.

Password spraying is an online password-guessing attack that turns brute force on its side. Instead of many passwords against one account, the attacker tries one or a few likely passwords, such as a season and year, against a long list of usernames, then pauses before the next round. MITRE ATT&CK lists it as a sub-technique of brute force. Because each account sees only a handful of failures, per-account account lockout and clipping level thresholds are commonly never reached, and one weak password among many users is enough.

It differs from a dictionary attack, which runs a word list against one account or a stolen hash, and from credential stuffing, which replays username and password pairs leaked from another breach. The defences that help work across accounts rather than per account: screening new passwords against a blocklist of common values, which NIST SP 800-63B-4 requires; monitoring for failed logons spread over many accounts from one source; and multi-factor authentication, which means a correctly guessed password is not enough on its own.

Exam relevance: a scenario is likely to describe a few failures on each of many accounts, with no lockouts triggered. Candidates are expected to identify spraying from that pattern and to recognise that a tighter lockout threshold does little against it, while blocklists, cross-account monitoring and MFA address it.