Accounts & identity
Password spraying
Password spraying
An identity and access attack involving password spraying that can compromise an online account or authenticated session.
Fiche de sensibilisationPrête à diffuser à vos équipes ou clients
MIGHT YOU BE AFFECTED?
Turn knowledge into action.
How does this work?
Password spraying relies on a technical weakness, stolen access or human manipulation. The exact mechanism depends on the target and the attacker’s objective.
REAL-WORLD EXAMPLE
« A victim or organisation encounters signs consistent with password spraying and must verify the event before taking further action. »
Typical sequence
- 1Initial access or contact
- 2Exploitation, manipulation or persistence
- 3Impact on accounts, systems or data
Warning signs
- Unexpected activity or security alerts
- Unfamiliar access, software or network behaviour
- Pressure, disruption or unexplained changes
How to protect yourself
- Keep systems and applications up to date
- Use strong access controls and phishing-resistant MFA
- Monitor unusual activity and preserve reliable backups
If you think you are affected
Stop the affected activity, isolate exposed devices or accounts, preserve evidence, revoke suspicious access and contact the appropriate security professional.
Last updated: 6 September 2026