
Password spraying is a bulk guessing technique: attackers try a few common passwords across many accounts instead of hammering one user with thousands of guesses. That helps them stay under lockout thresholds while still finding the one person using a weak seasonal password.
Defense starts with unique passphrases and MFA. Official primers: CISA — Turn on MFA, Microsoft two-step verification, and Google 2-Step Verification.
Signs your business is a soft target
- Shared passwords between staff
- No MFA on email
- Local admin passwords reused across PCs
- Old accounts for former employees still enabled
- VPN or remote desktop exposed with weak passwords
Best practices that actually work
- Require MFA on email and remote access—no exceptions for owners
- Use a password manager and unique passphrases (length beats clever substitutions)
- Block known-bad passwords where your platform allows
- Disable legacy authentication protocols that bypass modern MFA
- Review sign-in logs weekly for impossible travel and flood attempts
- Offboard users the same day they leave
What to do after a suspected spray
Reset affected passwords, revoke sessions, confirm MFA methods, and have IT check for inbox rules and new app consents. Review Microsoft account security or Google Account Security for unexpected devices and apps.
Official resources
- CISA: Turn on MFA
- Microsoft two-step verification
- Microsoft account security
- Google 2-Step Verification
- Google Account Security
SabatAge helps SMBs tighten identity security without drowning staff in complexity. Layered security · Contact · (845) 475-8468.

Comments are closed