Filed under: Cybersecurity — Microsoft 365 Login Security — August 2026
What happened
Security firm Huntress reports that password-spraying attacks — where hackers try stolen or guessed passwords across many accounts at once — jumped 155x in the first half of 2026. The worst case: a June campaign against Microsoft’s sign-in system generated over 81 million login attempts in two weeks and compromised 78 accounts. Attackers exploited an old sign-in method (ROPC) that sends a password straight through without ever triggering a multi-factor authentication (MFA) prompt.
Why it matters to your business
Most Phoenix small businesses run on Microsoft 365, and many assume MFA means they’re covered. Huntress found that among the businesses hit, a third had no MFA at all — and every business that did have MFA still got breached anyway, because their policies only covered certain apps or users, relied on “trusted locations,” or were left running in report-only mode instead of actually enforcing anything. Half-on MFA can be worse than no MFA if it gives you false confidence.
What to do this week
Have whoever manages your Microsoft 365 tenant open the Entra admin center (entra.microsoft.com) and check Protection > Conditional Access: confirm MFA policies apply to all users and all apps, not a subset, and that none are stuck in “Report-only” mode. Under Protection > Authentication methods, disable legacy authentication protocols including ROPC if your business doesn’t specifically need them. If you don’t have Conditional Access licensing, turn on Security Defaults, which blocks legacy auth by default. Also glance at recent sign-in logs for spikes in failed login attempts from unfamiliar locations.
The bigger picture
Attackers have shifted from breaking passwords to finding the gaps between where MFA is supposed to apply and where it actually does — a reminder that security settings need to be checked, not just switched on once and forgotten. — Password spraying attacks surge 155x as hackers exploit MFA gaps
Not sure if your MFA actually covers everyone? Book a free consult — https://micro1tech.com/contact/