Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Password Spraying Attacks Surge 155x: What the Azure CLI Campaign Reveals About MFA Gaps

What Happened

Huntress reported a 155-fold rise in password spraying attacks during the first half of 2026, with a campaign targeting Microsoft Azure CLI accounting for a major share of the increase. Attackers used the OAuth Resource Owner Password Credentials flow, a legacy authentication method deprecated in OAuth 2.1 but still active in many tenants, to validate stolen and guessed credentials directly against Azure and Entra accounts. Traffic tied to hosting provider LSHIY generated more than 81 million login attempts and compromised 78 accounts in a single two-week window in mid-June. After LSHIY suspended the offending customer, attackers shifted to a different hosting provider and continued the campaign under new IP ranges. Huntress found every affected organization shared some form of MFA weakness, including policies enforced for only certain user groups, only non-trusted locations, or not enforced at all.

Why This Matters for Canadian Organizations

Microsoft 365 and Azure underpin daily operations across Canadian government departments, financial institutions, and enterprises of every size, and the ROPC authentication flow remains active by default in many tenants without administrators realizing it bypasses modern conditional access checks. A 155-fold increase signals attackers found a repeatable, low-cost method for testing large credential lists against cloud identity infrastructure, and any Canadian organization with incomplete MFA coverage across its cloud applications carries the same exposure this campaign already found and exploited elsewhere. Organizations under OSFI Guideline B-13 face specific expectations around strong authentication controls for critical systems, and gaps in MFA enforcement represent exactly the kind of control weakness examiners look for. Successful account compromise involving customer or employee personal information also triggers breach notification duties under PIPEDA.

What to Do

Security teams should audit MFA enforcement across every cloud application and user group rather than assuming a single tenant-wide policy covers all sign-in paths, and disable the legacy ROPC authentication flow unless a specific, documented business need requires it. Monitoring for high-volume authentication attempts from unfamiliar IP ranges, particularly against Azure CLI and similar administrative tooling, helps catch spraying activity before it results in account compromise. Full detail on the campaign is available from BleepingComputer and Huntress.

Enjoy this article? Don’t forget to share.