Password spraying is not new, but Huntress says the scale and authentication path have changed. According to BleepingComputer, the security firm observed a 155x increase in password-spraying attacks in the first half of 2026, including one campaign that produced more than 81 million related login attempts in a two-week period in mid-June. The campaign targeted Microsoft’s Azure CLI, the command-line tool administrators use to manage Azure and Entra resources, BleepingComputer reports. Huntress tied the traffic to an IPv6 range controlled by internet hosting provider LSHIY LLC. In the same two-week mid-June window, Huntress observed 78 account compromises associated with the activity. The mechanics were familiar but effective. As described by BleepingComputer, attackers collect valid usernames from sources such as LinkedIn, company websites, breach dumps, and phishing, then test a short list of breached or common passwords across many accounts. Rather than repeatedly hammering one account, password spraying spreads attempts across a user list and waits between rounds to reduce the chance of triggering lockout controls. Huntress said the LSHIY-linked campaign combined large-scale spraying with the reuse of valid username-and-password pairs from earlier breaches that had not been rotated. That matters because a reused credential is not merely a weak guess; if it still works, it can give an attacker a real foothold for lateral movement, business email compromise, data exfiltration, or further credential theft. The more important weakness was in the authentication flow. BleepingComputer reports that the attackers abused Resource Owner Password Credentials, or ROPC, a legacy OAuth grant deprecated in OAuth 2.1. ROPC sends the username and password directly to the token endpoint and does not support modern interactive authentication flows such as multi-factor authentication or single sign-on. That created a gap for organizations that believed they had multi-factor authentication in place. According to BleepingComputer, many of the compromised businesses used MFA through a Conditional Access Policy, but the policy was not configured to cover the specific flow the attackers used. In those cases, MFA existed, but not at every path where a password could still be exchanged for access. BleepingComputer also reports that Huntress saw no post-compromise activity after the successful logins linked to the LSHIY campaign. Rich Mozeleski, a staff product manager at Huntress, suspected the attacker may have been validating credentials for resale on the dark web, though that remains an assessment rather than a confirmed downstream use. LSHIY later terminated the attacks from the original IP range and confirmed that the attacker had used its bring-your-own-IP offering, according to the report. Bring-your-own-IP is a legitimate service that lets customers route traffic through a provider using IP ranges they control, but BleepingComputer notes that the flexibility can also complicate IP-based blocking and detection when abused by attackers. Who benefits: Attackers benefit when organizations leave older authentication flows reachable and when breached passwords are not rotated. Security teams benefit from auditing Conditional Access Policy coverage against the specific flows still allowed in their environments. Who's exposed: Organizations using MFA but leaving Resource Owner Password Credentials or similar legacy flows outside policy coverage are exposed. Businesses with reused credentials from past breaches are especially vulnerable to this type of spraying campaign.