Avatier

Phished or stolen credentials

Password spraying

Also called: password spray

Password spraying is a brute-force attack that tries a few common passwords against many accounts, instead of many passwords against one account. Keeping attempts per account low avoids lockouts and alerts. It succeeds when even one user in an organization has a weak or predictable password and no second factor protecting the account.

How it works

The attacker gathers a list of usernames, often from email formats or public staff lists, then tries one likely password such as a season and year across all of them. After a pause, they try the next password. Cloud sign-in portals, VPNs and remote access services are frequent targets.

A real example

In an October 2024 advisory, CISA, the FBI and partners said that since October 2023 Iranian actors had used brute force, such as password spraying, and MFA push bombing to compromise user accounts and gain access to organizations.

Source: Iranian Cyber Actors' Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations (AA24-290A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-10-16

The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Require MFA on every externally reachable sign-in, ban common and breached passwords, and alert when many accounts see failed logins from the same source.

Related terms

Threat actors that use it

  • Akira

    Profile with government sources

  • APT29

    Profile with government sources

Sources

  1. Iranian Cyber Actors' Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations (AA24-290A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-10-16

Last reviewed Oct 2, 2026