They remain effective because attackers can test large numbers of common or reused passwords at scale, and a single weak account can open the door to broader compromise. When MFA is missing or misconfigured, the attacker’s success rate rises sharply. Defenders need strong password policy enforcement, detection for abnormal login patterns, and controls that limit repeated authentication attempts.
Why Password Spraying Still Works Against Enterprise Accounts
password spraying remains effective because it targets the operational reality of enterprise authentication rather than trying to defeat a single account with heavy guessing. Attackers spread a small set of common passwords across many accounts, which helps them stay below lockout thresholds while still finding weak or reused credentials. The method also benefits from the uneven state of enterprise controls: some apps enforce rate limits, some do not; some accounts use MFA, others are excluded; and some identities are more exposed through remote access, legacy protocols, or helpdesk workflows. The result is a low-cost, scalable attack that keeps working wherever policy is inconsistent.
Brute-force attacks are less subtle but still persist where accounts expose weak passwords, poor throttling, or permissive recovery paths. They are especially effective when defenders rely on password complexity alone and do not pair it with detection, conditional access, or stronger authentication. In practice, the weakness is usually not that enterprises have no controls at all, but that the controls are fragmented, unevenly enforced, or bypassed for convenience.
For the broader control pattern behind this problem, NIST’s guidance on authentication and access control aligns with the need for rate limiting, strong authentication, and monitoring, while the MITRE ATT&CK Enterprise Matrix helps teams think about credential access as a repeatable intrusion path rather than a one-off event. In practice, many security teams only discover the exposure after repeated logins begin appearing across multiple accounts, by which point the attacker has already identified the easiest targets.
How Enterprises Make These Attacks Easier Than They Should Be
The practical mechanics are straightforward. Password spraying works best when attackers can test a small password set across many usernames, often using cloud login portals, VPNs, webmail, or federation endpoints that expose common authentication patterns. If the environment tolerates many failed attempts before triggering friction, the attacker can probe slowly and blend in with normal traffic. Brute-force attacks become viable when an account has a weak password, when rate limits are too lenient, or when legacy services still accept password-only authentication.
Defenders often underestimate the importance of control consistency. A strong password policy on paper does little if service accounts, guest accounts, contractors, regional systems, or older applications are exempted. The same issue appears with MFA: if it is optional, inconsistently enforced, or excluded for certain paths, attackers will route around the strongest protected entry points and target the weakest ones. Detection matters just as much as prevention. Successful defense usually depends on spotting abnormal authentication patterns such as distributed attempts, repeated failures across many usernames, or logins from unusual geographies or devices.
Identity telemetry is therefore the key signal. Teams need to correlate failed sign-ins, source IP reputation, user-agent anomalies, impossible travel patterns, and sudden bursts of attempts against a broad user set. That is why framework guidance such as the MITRE ATT&CK Enterprise Matrix is useful here: it frames credential attacks as a chain of observable behaviours, not just an authentication event. NHIMG’s coverage of The 52 NHI breaches Report is also relevant because the same blast-radius logic applies when one compromised identity unlocks broader systems, even if the initial issue began with a human account. These attacks tend to break down only when organisations combine throttling, strong authentication, and alerting across every exposed login surface, because any unprotected edge becomes the path of least resistance.
Where the Usual Defenses Break Down
Tighter authentication controls often increase user friction, so organisations have to balance usability against the risk of credential-based intrusion. The common failure case is not a complete lack of controls, but exceptions: legacy protocols, shared accounts, privileged bypasses, and recovery flows that are easier to abuse than primary login. Current guidance suggests treating those exceptions as part of the attack surface, not as administrative edge cases.
Another edge case is automation by the attacker. Once a password spray succeeds against one account type, the same credentials may be reused for other portals, internal apps, or connected services. That means the first compromise is often only the beginning. Teams should also distinguish between noisy brute force and quieter spraying, because the latter may never trigger classic lockout-based alerts. In environments with federation, remote workforce access, or multiple identity providers, the attack surface fragments quickly and defenders lose the benefit of a single consistent policy.
The safest posture is to assume that some passwords will be guessed and then reduce the value of that guess. That means minimising standing access, enforcing MFA where it matters most, and making failed authentication visible enough to investigate before the attacker finds a workable path. The main lesson is that these attacks stay effective wherever enterprises treat authentication as a one-time gate instead of a continuously monitored control plane.
Risk and Threat Considerations
Password spraying and brute-force attacks create material exposure because they exploit predictable human credential choices and uneven enforcement of authentication controls. The risk is not limited to one account: a single successful login can expose internal mail, SaaS consoles, remote access, or privileged workflows that were never meant to be reachable through password guessing alone.
Failure mechanism: Attackers distribute attempts across many accounts or repeatedly test one account until they find weak credentials, while staying under lockout and detection thresholds. The mechanism becomes more effective when MFA is absent, recovery paths are weak, or legacy authentication endpoints remain enabled.
Impact: A successful guess can lead to account takeover, data exposure, privilege escalation through chained access, and persistence through password changes if adjacent recovery or delegated access paths are not contained.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1110 — Brute Force | Covers password spraying and brute-force credential guessing against accounts. |
| Recommendation — Map repeated login attempts to T1110 and alert on distributed credential-testing patterns. | ||
| CIS Controls v8 | 5 — Account Management | Applies to account lifecycle, MFA enforcement, and privileged access restrictions. |
| Recommendation — Enforce account policies and MFA consistently across all exposed login paths. | ||
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication, and Access Control | Directly addresses authentication strength and access-control consistency. |
| DE.CM — Security Continuous Monitoring | Relevant for detecting abnormal login bursts and credential-attack patterns. | |
| Recommendation — Strengthen authentication and access controls across every user-facing access surface. Correlate failed-logon telemetry to detect spraying before account takeover succeeds. | ||
Practitioner Guidance
What to prioritise: Focus first on the identities and authentication paths that create the largest blast radius, not on every account equally. Privileged users, remote access portals, and federated sign-in paths deserve the strongest controls because those are the routes attackers target once they find a weak password.
What to verify: Confirm that lockout, throttling, and MFA policies are enforced consistently across all login surfaces, including legacy and exception paths. If one path is weaker than the others, attackers will use that path to bypass the rest.
Decision rule: If a password-only or lightly protected login path still exists for a production identity, treat it as a high-risk exposure until it is either removed or wrapped in stronger authentication and monitoring.
What to measure: Track failed-login bursts, distributed attempt patterns, and the share of sign-ins covered by strong authentication. A control is only working if the telemetry would let you distinguish normal user error from deliberate credential testing.
Practitioner takeaway: The real objective is not to make guessing impossible, but to make every successful guess small, visible, and non-transferable to the rest of the environment.
Related resources from NHI Mgmt Group
- Why do static password filters leave enterprise accounts exposed to credential stuffing and spray attacks?
- What is the difference between password spraying and brute-force attacks?
- Why do password spraying attacks succeed so often against third-party accounts?
- Why is password spraying so effective against Active Directory and Entra ID?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org