Header image

Huntress has observed a 155x increase in password spraying attacks in the first half of 2026. Brute force is old news, but the spin driving that spike is new.

One major contributor was  a campaign targeting Microsoft's Azure CLI, the command-line tool admins use to manage Azure and Entra resources. The traffic originated from an IPv6 range controlled by internet hosting provider LSHIY LLC.

The campaign started months earlier, but in mid-June alone Huntress observed more than 81 million related login attempts and 78 account compromises in a two-week window.

June 2026 password-spraying spike tied to the LSHIY campaign. 
June 2026 password-spraying spike tied to the LSHIY campaign. 

The auth flow that time forgot

A typical password spraying attack follows a familiar pattern:

  1. 1. Reconnaissance: The attacker collects valid usernames via LinkedIn, company websites, data breach dumps, and phishing to create a target list.

  2. 2. Build password list: The attacker assembles a short list of breached passwords, common passwords such as "Password123," company name variants, or seasonal terms.

  3. 3. Spray across accounts: The attacker tries one password against every account on the target list. Heeding lockout thresholds, they wait before moving to the next password in a low and slow approach.