Credential stuffing and password spraying are automated attacks that try to log in to your accounts with leaked or guessable passwords. Multi-factor authentication (MFA) defeats the vast majority of them, because a correct password alone is no longer enough.
Most attacks on small businesses don't start with exotic malware. They start with someone trying to sign in with a password they didn't earn. These two techniques are the most common automated ways of doing it, and they run constantly against cloud services such as Microsoft 365 and Google Workspace, whether or not anyone is targeting your business in particular.
Credential stuffing uses username and password pairs leaked in earlier data breaches to try logins at other services. The attacker doesn't guess anything. They already hold real credentials from real people, taken from breaches of unrelated websites.
Billions of leaked credential pairs are in circulation. Attackers feed them into tools that try logins across many services at once. The success rate for any single pair is low, but at that volume even a tiny hit rate produces a lot of compromised accounts.
It works because of password reuse. When someone uses the same password for a shopping site and their work email, a breach of the shopping site exposes the work account too.
The defenses: MFA, so a correct password isn't enough on its own, and a password manager so staff stop reusing passwords. Dark web monitoring, available from NerdSquad as an add-on, can flag exposed work credentials so they can be changed before someone tries them.
Password spraying flips the approach. Instead of many passwords against one account, it tries one common password against many accounts. The attacker picks something like "Winter2025!", "Welcome1" or "Company123" and tries it against every account they can find in your organization.
The reason is account lockout. Most services lock an account after several failed attempts. One hundred guesses against one account triggers that lockout; one guess against one hundred accounts usually doesn't.
Spraying works especially well against predictable password habits. If staff must change passwords every 90 days and they do it by bumping a number or a season, an attacker can make a good guess at the current one. Current NIST guidance discourages forced periodic changes for this reason and favors long passphrases, screening against known-breached passwords and MFA.
The defenses: MFA again, plus password rules enforced by technical controls rather than a policy document. Microsoft Entra ID (formerly Azure AD) includes Smart Lockout, which helps throttle repeated guessing. More advanced risk-based detection of spray patterns is part of Entra ID Protection, which depends on your Microsoft 365 licensing. We review what your licenses include and configure it as part of our Microsoft 365 support.
Failed sign-in attempts from automated tools show up regularly in the logs of ordinary small business Microsoft 365 tenants. Most of it is background noise. For accounts with MFA enforced, the attacker enters a correct password, hits the MFA prompt and gets no further.
For an account without MFA, a correct leaked password means a successful login. Here's a typical scenario: the attacker signs in quietly, creates a mail-forwarding rule so copies of messages go to an outside address, watches for invoices and wire instructions, and weeks later uses the access for business email compromise. Nobody notices until a payment goes to the wrong account.
Microsoft has published research showing that MFA blocks more than 99% of automated account compromise attacks. Credential stuffing and password spraying make up a large share of those attacks, and both depend on the password being the only thing standing in the way.
MFA is not a force field. Attackers can still get past it with "MFA fatigue" (spamming push prompts until someone taps Approve), with phishing pages that relay the login in real time, or by stealing session tokens. That is why we pair MFA with number matching or phishing-resistant methods where possible, conditional access rules, monitoring for risky sign-ins and regular security awareness training.
MFA is the identity layer of Zero Trust. Zero Trust assumes a correct password is not enough proof of identity, so every access request is checked against additional signals such as the second factor, device health, location and behavior. MFA is the most basic of those checks and the one that stops most automated attacks early.
For our managed IT clients, MFA is required. We turn it on during onboarding, require it for new accounts as part of the new employee setup process, and review account security settings so accounts without MFA get followed up. It is part of the cybersecurity services we build for every client.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.
Related: Microsoft 365 support and security