Password spraying surges 155× in 2026 by slipping through MFA blind spots
Huntress measured a 155× increase in password spraying attacks in the first half of 2026, driven by an LSHIY campaign that generated 81 million login attempts in two weeks through the ROPC flow. Security teams must disable ROPC and extend MFA to every authentication flow, with no exceptions.