Password Spraying Attacks Jump 155x: What M365 Tenants Should Do Now

What happened
Threat researchers at Huntress are reporting a staggering 155x jump in password spraying activity in the first half of this year, including one campaign that hammered targets with more than 81 million login attempts over just two weeks. According to reporting by BleepingComputer, the attackers are specifically hunting for accounts that still allow legacy authentication protocols and for login flows where multi-factor authentication (MFA) isn't uniformly enforced.
Password spraying is the quieter cousin of brute force: instead of pounding one account with thousands of passwords, attackers try a handful of common passwords against thousands of accounts, staying under lockout thresholds. When even one identity slips through an unprotected legacy endpoint, they're inside your tenant.

Why this matters for Pittsburgh SMBs
If your business runs on Microsoft 365, this is your threat model, full stop. Pittsburgh's professional services firms, CPA practices, law offices, healthcare groups, and Mon Valley manufacturers are exactly the profile these campaigns target: small enough that identity hygiene often has gaps, valuable enough that a single compromised mailbox pays off through wire fraud, W-2 theft, or client-data extortion. We routinely see tenants that were configured years ago with MFA "mostly on" — meaning it's on for the Outlook desktop client but silently bypassed for an old IMAP connector, a shared service account, or a PowerShell login flow nobody remembers creating.
The compliance stakes are just as sharp. For CPA and financial services clients under the FTC Safeguards Rule, MFA on any system with customer information is not optional. Healthcare clients under HIPAA face the same expectation through the Security Rule's access-control requirements. Defense contractors moving toward CMMC Level 2 have explicit identification and authentication controls under NIST 800-171 that a legacy-auth gap will fail on the spot. And for anyone pursuing SOC 2, a password-spray incident that traces back to disabled MFA is the kind of finding that torpedoes a Type II report.
The uncomfortable part: attackers don't need to be sophisticated. They need you to have one forgotten mailbox, one break-glass admin without a phishing-resistant second factor, or one Conditional Access policy with an "exclude" that outlived its reason.
What to do about it this week
Here's a concrete checklist you (or your IT provider) can start on Monday. None of this requires new licensing beyond what most Business Premium or E3/E5 tenants already have.
- Pull an MFA coverage report. In Entra ID, run the Authentication Methods activity report and the "users without MFA" report. Any account — including service accounts, shared mailboxes with sign-in enabled, and admin break-glass accounts — needs an owner and a documented control. If you can't produce that list today, that is finding #1.
- Kill legacy authentication. Basic auth for Exchange Online is officially retired, but tenants created years ago often still have SMTP AUTH, POP, IMAP, or legacy MAPI paths enabled per-mailbox. Set a Conditional Access policy that blocks legacy authentication tenant-wide, then remediate the handful of apps that scream.
- Enforce phishing-resistant MFA for admins. Global admins, Exchange admins, and anyone with privileged role assignment should be on FIDO2 keys or Windows Hello for Business — not SMS, and ideally not push notifications alone. Attackers are burning through MFA-fatigue prompts on the regular.
- Turn on risk-based sign-in policies. If you have Entra ID P1 or P2, configure sign-in risk and user risk policies to force step-up authentication or block on high risk. Review the sign-in logs for impossible-travel and anonymous-IP hits weekly.
- Rotate and audit service accounts. Any non-human account with a password older than a year, no MFA, and mailbox access is a spray target. Move them to managed identities or workload identities where possible; where not, put them behind Conditional Access location and device filters.
- Set alerting for password spray patterns. In Microsoft Defender for Identity or your SIEM, alert on high-volume failed sign-ins from a single ASN across many usernames. If you don't have visibility into that today, that's a gap your cybersecurity stack should close.
- Refresh the incident-response runbook. Confirm who disables an account, revokes sessions, and notifies clients within the first hour of a suspected compromise. If the answer is "we'd figure it out," fix that before you need it.
A reasonable target: have items 1–3 done inside two weeks, and items 4–7 inside 60 days (by mid-October, working from today). If you're a DoD supplier, tie the work to your NIST 800-171 SSP so it counts toward your assessment evidence.

How PGH Networks helps
Identity hardening is baked into how we run managed IT and Microsoft 365 for Pittsburgh SMBs — from Conditional Access design and legacy-auth cleanup to ongoing monitoring for spray and token-theft patterns. For regulated clients, our vCIO team maps the same controls to your HIPAA, SOC 2, FTC Safeguards, or CMMC obligations so one project produces both security and audit evidence. If you're not sure where your tenant stands, we'll run a focused Microsoft 365 identity assessment and hand you a prioritized fix list.
Talk to us
Call 724.888.7007 or reach out through the contact form and we'll get a review on the calendar this week.
Related reading

CISA Flags Critical macOS, SharePoint, vCenter, and Windows IKE Bugs
CISA added actively exploited macOS, SharePoint, vCenter, and Windows IKE flaws to its KEV catalog. Here is what Pittsburgh SMBs should patch and verify this week.

Active SharePoint Exploit: What Pittsburgh SMBs Should Do Now
Attackers are exploiting a critical Microsoft SharePoint flaw in the wild. Here is what Pittsburgh SMBs should verify, patch, and monitor this week.

CISA Warns: SharePoint Flaw Now Used in Ransomware Attacks
CISA confirms ransomware crews are exploiting a SharePoint RCE flaw. Here is what Pittsburgh SMBs should patch, verify, and monitor this week.