Think your password is strong enough? Hackers are hoping you're wrong.
Security researchers recently uncovered a massive attack against Microsoft 365 accounts in which cybercriminals generated more than 81 million login attempts over a two-week period. Instead of guessing thousands of passwords for one account, the attackers used a technique known as password spraying.
Here's how it works.
Criminals take usernames and passwords that have been exposed in previous data breaches and try them across large numbers of accounts. Because many people reuse the same password on multiple websites, a password stolen years ago from an unrelated compFany may still unlock an email or business account today.
Researchers say the campaign successfully compromised dozens of accounts across multiple organizations, showing that even businesses with security protections can be vulnerable if passwords are reused or account protections are not properly configured. In this case, the Conditional Access policies were misconfigured in how they related to MFA (multi-factor authentication).
The good news is that protecting yourself doesn't require advanced technical skills.

Start by using a unique password for every important account. If one website is breached, criminals won't be able to use that same password elsewhere. Enable multi-factor authentication whenever it's available, and consider using a reputable password manager to create and store strong, unique passwords, if you can’t remember all of them. Just keep in mind that if there is a breach of the password management company, all of your passwords are at risk of being accessed.
It's also a good idea to pay attention to unexpected login alerts or password reset notifications. They may be an early warning that someone is trying to access your account.
What’s the difference between password spraying and credential stuffing, you might be asking? Well, they’re related, but slightly different. While credential stuffing uses exposed passwords that were previously stolen from a data breach, password spraying relies more on speed and common passwords. For example, that list of most used passwords that comes out at the beginning of every year has a lot of those commonly used passwords. In the United States, the one taking the top spot nearly every year for…. well…. ever, is “password.” Other examples are “123456,” “passw0rd” and “football.” It also may take advantage of passwords that were stolen in previous incidents, but never changed.
It’s just another reason to create your own, unique, difficult to guess password for each and every account you log into online.
The Cybersecurity company Huntress saw this attack and noted that it targeted 78 Microsoft accounts across 64 organizations.
Cybercriminals aren't always breaking down digital doors. Sometimes they're simply trying old keys and hoping one still fits. Making each password unique can help ensure yours isn't the one that opens the door.