---
title: New Threat Alert From The FBI – Password Spraying
description: New Threat Alert From The FBI – Password Spraying
image: https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/ThinkstockPhotos-840534924-1.jpg
---

[Skip to the main content.](https://ontimetech.valeonetworks.com/blog/tech-tips/new-threat-alert-from-the-fbi-password-spraying#main-content)

[![OTT powerd by VN big](https://ontimetech.valeonetworks.com/hs-fs/hubfs/OTT%20powerd%20by%20VN%20big.png?width=500&height=175&name=OTT%20powerd%20by%20VN%20big.png "OTT powerd by VN big")](https://ontimetech.valeonetworks.com)

[![OTT powerd by VN big](https://ontimetech.valeonetworks.com/hs-fs/hubfs/OTT%20powerd%20by%20VN%20big.png?width=500&height=175&name=OTT%20powerd%20by%20VN%20big.png "OTT powerd by VN big")](https://ontimetech.valeonetworks.com)

- [Services](https://ontimetech.valeonetworks.com/our-services/) 
    - [Managed It Services](https://ontimetech.valeonetworks.com/our-services/managed-it/)
    - [Cybersecurity](https://ontimetech.valeonetworks.com/our-services/cybersecurity/)
    - [Cloud Solutions](https://ontimetech.valeonetworks.com/our-services/cloud-solutions/)
    - [Compliance](https://ontimetech.valeonetworks.com/our-services/compliance/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources](https://ontimetech.valeonetworks.com/resources/) 
    - [Blog](https://ontimetech.valeonetworks.com/blog)
- [About](https://ontimetech.valeonetworks.com/about/) 
    - [Client Testimonials](https://ontimetech.valeonetworks.com/testimonials/)

[415-294-5250](tel:4152945250) [Client Portal](https://portal.Valeonetworks.com)

Toggle Menu

Toggle Menu

[415-294-5250](tel:4152945250) [Client Portal](https://portal.Valeonetworks.com)

- [Services *Toggle Menu*](https://ontimetech.valeonetworks.com/our-services/) 
    - [Managed It Services](https://ontimetech.valeonetworks.com/our-services/managed-it/)
    - [Cybersecurity](https://ontimetech.valeonetworks.com/our-services/cybersecurity/)
    - [Cloud Solutions](https://ontimetech.valeonetworks.com/our-services/cloud-solutions/)
    - [Compliance](https://ontimetech.valeonetworks.com/our-services/compliance/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources *Toggle Menu*](https://ontimetech.valeonetworks.com/resources/) 
    - [Blog](https://ontimetech.valeonetworks.com/blog)
- [About *Toggle Menu*](https://ontimetech.valeonetworks.com/about/) 
    - [Client Testimonials](https://ontimetech.valeonetworks.com/testimonials/)

- Example Link
- Example Link
- Example Link

[*Facebook*](https://ontimetech.valeonetworks.com/blog/tech-tips/new-threat-alert-from-the-fbi-password-spraying#0) [*Instagram*](https://ontimetech.valeonetworks.com/blog/tech-tips/new-threat-alert-from-the-fbi-password-spraying#0) [*LinkedIn*](https://ontimetech.valeonetworks.com/blog/tech-tips/new-threat-alert-from-the-fbi-password-spraying#0) [*Twitter*](https://ontimetech.valeonetworks.com/blog/tech-tips/new-threat-alert-from-the-fbi-password-spraying#0) [*Youtube*](https://ontimetech.valeonetworks.com/blog/tech-tips/new-threat-alert-from-the-fbi-password-spraying#0) [*Medium*](https://ontimetech.valeonetworks.com/blog/tech-tips/new-threat-alert-from-the-fbi-password-spraying#0)

 4 min read

# New Threat Alert From The FBI – Password Spraying

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) :  May 10, 2018, 10:18:55 AM

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services)

**7 Steps To Protect Yourself**

You probably use a number of personal identification numbers (PINs), passwords, and passphrases to get money from ATMs, to use your debit card when shopping, or to log in to your personal or business email. Hackers represent a real threat to both your personal and business password security and confidential information. Now, these criminals are using a technique called Password Spraying to steal your information.

![Password Spraying](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Blog%20Images/Imported_Blog_Media/ThinkstockPhotos-840534924-1.jpg?width=509&height=339&name=ThinkstockPhotos-840534924-1.jpg)

According to information derived from FBI investigations, malicious cyber actors are increasingly using password spraying against organizations in the United States and abroad. In February 2018, the Department of Justice in the Southern District of New York [indicted nine Iranian nationals, who were associated with the Mabna Institute,](mailto:https://www.justice.gov/usao-sdny/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic) for computer intrusion offenses. However, password spraying isn’t limited to this group. Other hackers are using it to gain access to both personal and business confidential information.

Manhattan U.S. Attorney Geoffrey S. Berman said: “Today, in one of the largest state-sponsored hacking campaigns ever prosecuted by the Department of Justice, we have unmasked criminals who normally hide behind the ones and zeros of computer code. As alleged, this massive and brazen cyber-assault on the computer systems of hundreds of universities in 22 countries, including the United States, and dozens of private sector companies and governmental organizations was conducted on behalf of Iran’s Islamic Revolutionary Guard. The hackers targeted innovations and intellectual property from our country’s greatest minds. These defendants are now fugitives from American justice, no longer free to travel outside Iran without risk of arrest. The only way they will see the outside world is through their computer screens, but stripped of their greatest asset – anonymity.”

**How Does Password Spraying Work?**

Password spraying is a type of brute force attack where hackers use a username with multiple passwords to gain access to your IT system. With traditional brute force attacks, the criminal uses one username with multiple passwords. Employing a lockout functionality, which locks the criminal out after a set number of login attempts, is an effective means of dealing with traditional brute force attacks.

However, with a password-spray attack (also known as the “low-and-slow” method), the malicious cyber actors use a single password against many accounts before moving on to another password. They continue this process until they find one that works. This strategy works for them because they can avoid account lockouts. It circumvents lockout functionality by using the most common passwords against multiple user accounts until they find one that works.

Password spraying targets single sign-on (SSO) and cloud-based applications using federated authentication. A federated authentication identity provides single access to multiple systems across different enterprises. Criminals target federated authentication protocols because it disguises their activities and ensures their anonymity.

Attackers use password spraying in environments that don’t use multi-factor authentication (MFA), rely on easy-to-guess passwords, or use SSO with a federated authentication method.

 

**Your Email Is Also At Risk**

Hackers also prey on email accounts that use inbox synchronization (which pulls emails from the Cloud to inboxes on remote devices). Malicious actors use inbox synchronization to obtain unauthorized access to your organization’s email directly from the Cloud. Then they download email to locally stored files, identify your company’s email address list, and secretly apply inbox rules to forward your sent and received messages to them.

The United States Computer Emergency Readiness Team (US-CERT) details how hackers use password spraying, what you should watch out for, who is at risk, and the impact this type of attack can have on your organization.

Your Technology Service Provider can explain this to you and your employees in plain language, and help you protect your organization against password spraying and other attacks.

**Traditional Tactics Techniques & Procedures**

- Using social engineering tactics to perform online research (i.e., Google search, LinkedIn, etc.) to identify target organizations and specific user accounts for initial password spray
- Using easy-to-guess passwords (e.g., “Winter2018”, “Password123!”) and publicly available tools, execute a password spray attack against targeted accounts by utilizing the identified SSO or web-based application and federated authentication method
- Leveraging the initial group of compromised accounts, downloading the Global Address List (GAL) from a target’s email client, and performing a larger password spray against legitimate accounts
- Using the compromised access, attempting to expand laterally (e.g., via Remote Desktop Protocol) within the network, and performing mass data exfiltration using File Transfer Protocol tools such as FileZilla

**Indicators That You’ve Been Attacked**

- A massive spike in attempted logins against the enterprise SSO portal or web-based application;
- Using automated tools, malicious actors attempt thousands of logons, in rapid succession, against multiple user accounts at a victim enterprise, originating from a single IP address and computer (e.g., a common User Agent String).
- Attacks have been seen to run for over two hours.
- Employee logins from IP addresses resolving to locations inconsistent with their normal locations.

**Typical Victim Environment**

The vast majority of known password spray victims share some of the following characteristics:

- Use SSO or web-based applications with the federated authentication method
- Lack multifactor authentication (MFA)
- Allow easy-to-guess passwords (e.g., “Winter2018”, “Password123!”)
- Use inbox synchronization, allowing email to be pulled from cloud environments to remote devices
- Allow email forwarding to be set up at the user level
- Limited logging setup creating difficulty during post-event investigations

**The Impact**

A successful network intrusion can have severe impacts, particularly if the compromise becomes public and sensitive information is exposed. Possible impacts include:

- Temporary or permanent loss of sensitive or proprietary information;
- Disruption of regular operations;
- Financial losses incurred to restore systems and files; and
- Potential harm to an organization’s reputation.

**7 Steps You Can Take To Mitigate Password Spraying Attacks**

1. Enable MFA and review MFA settings to ensure coverage overall active, internet facing protocols.
2. Review password policies to ensure they align with the latest [NIST guidelines ](https://www.nist.gov/video/password-guidance-nist-0)and deter the use of easy-to-guess passwords.
3. Review IT helpdesk password management related to initial passwords, password resets for user lockouts, and shared accounts. IT helpdesk password procedures may not align with company policy, creating an exploitable security gap.
4. Many companies offer additional assistance and tools that can help detect and prevent password spray attacks, such as the
5. Make sure your employees change their corporate passwords every 60 days.
6. Establish a password policy that prohibits easy-to-guess passwords. Enable multi-factor authentication (MFA) for all web-based applications. If MFA practice is already in place, review current protocols thoroughly to ensure it is maintained well
7. Ask your Technology Solutions Provider to conduct Security Awareness Training for your employees at all levels.

**The FBI Reporting Notice**

The FBI would like you to report any suspicious or criminal activity to your FBI field office or the FBI’s 24/7 Cyber Watch (CyWatch). Field office contacts can be identified at [www.fbi.gov/contact-us/field](https://www.fbi.gov/contact-us/field-offices). CyWatch can be contacted by phone at (855) 292-3937 or by e-mail at [CyWatch@ic.fbi.gov](mailto:CyWatch@ic.fbi.gov).

Your report should include:

- The date,
- Time,
- Location,
- Type of activity,
- Number of people affected,
- Type of equipment used for the activity,
- The name of your company or organization, and
- A designated point of contact.

- [Tweet](https://twitter.com/share)

#### ![BusinessOwnerGuidetoM&A-1](https://ontimetech.valeonetworks.com/hs-fs/hubfs/BusinessOwnerGuidetoM%26A-1.png?width=303&height=209&name=BusinessOwnerGuidetoM%26A-1.png)

#### Download our eBook*THE ULTIMATE ROADMAP TO CMMC COMPLIANCE* by filling out the form below!

[![Important Warning From The FBI](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/GettyImages-942413760.jpg)](https://ontimetech.valeonetworks.com/blog/important-warning-from-the-fbi)

#### [Important Warning From The FBI](https://ontimetech.valeonetworks.com/blog/important-warning-from-the-fbi)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/lance-stone) : Jun 16, 2019, 9:43:00 PM

Hackers Now Using HTTPS To Trick Victims Via Phishing Scams

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/important-warning-from-the-fbi)

[![How MS Office Uses Collaboration & Other MS Office Features to Keep Its Place as the No. 1 Office Suite](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/ThinkstockPhotos-83121895.jpg)](https://ontimetech.valeonetworks.com/blog/how-ms-office-uses-collaboration-other-ms-office-features-to-keep-its-place-as-the-no-1-office-suite)

#### [How MS Office Uses Collaboration & Other MS Office Features to Keep Its Place as the No. 1 Office Suite](https://ontimetech.valeonetworks.com/blog/how-ms-office-uses-collaboration-other-ms-office-features-to-keep-its-place-as-the-no-1-office-suite)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) : Mar 16, 2017, 4:24:10 PM

While some see Office 2016 as nothing more than a cosmetic update to the venerable program, they are wrong. MS Office 2016 is a sea change for how we...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/how-ms-office-uses-collaboration-other-ms-office-features-to-keep-its-place-as-the-no-1-office-suite)

[![Important FBI/DHS Warning: Update On FBI and DHS Warning: SamSam Ransomware](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/GettyImages-1068277144.jpg)](https://ontimetech.valeonetworks.com/blog/important-fbi-dhs-warning-update-on-fbi-and-dhs-warning-samsam-ransomware)

#### [Important FBI/DHS Warning: Update On FBI and DHS Warning: SamSam Ransomware](https://ontimetech.valeonetworks.com/blog/important-fbi-dhs-warning-update-on-fbi-and-dhs-warning-samsam-ransomware)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/lance-stone) : Dec 7, 2018, 9:55:00 AM

The Department of Homeland Security and the Federal Bureau of Investigation issued a critical alert Dec. 3, warning users about SamSam ransomware and...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/important-fbi-dhs-warning-update-on-fbi-and-dhs-warning-samsam-ransomware)

![OTT White logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/VN%20-%20Division%20Logos/OTT%20Logo/OTT%20White%20logo.png?width=524&height=140&name=OTT%20White%20logo.png)

 

##### About

About

On Time Tech is an IT Support and Computer Services company serving California. We provide services to the areas in and around We know businesses like yours need technology support in order to run highly-effective organizations. Leverage pro-growth technology services for your company now.

##### Explore On Time Time

Explore On Time Time

- [Our Services](https://ontimetech.valeonetworks.com/our-services/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources](https://ontimetech.valeonetworks.com/resources/)
- [About](https://ontimetech.valeonetworks.com/about/)
- [Contact](https://ontimetech.valeonetworks.com/contact/)

##### Contact

Contact

**San Francisco:**  
1717 Fifth Ave  
San Rafael, CA 94901

[415-294-5250](tel:4152945250)

Business Hours:   
M-F: 8AM-9PM

- [Privacy Policy](https://ontimetech.valeonetworks.com/privacy-policy/)

© 2026 On Time Tech

[*Facebook*](https://www.facebook.com/ontimetechsf/)[*Twitter*](https://twitter.com/on_time_tech?lang=en)[*LinkedIn*](https://www.linkedin.com/company/ontimetech/)[*YouTube*](https://www.youtube.com/channel/UCubqs9PU_WWF-RFhfK9xNpw)

[![Alura White logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/VN%20-%20Division%20Logos/Alura%20White%20logo.png?width=295&height=115&name=Alura%20White%20logo.png)](https://alura.valeonetworks.com/) [![Next.I.T._White-Logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Next.I.T._White-Logo.png?width=328&height=136&name=Next.I.T._White-Logo.png)](https://next-it.net/) [![White-OTT-Logo-1-768x253](https://ontimetech.valeonetworks.com/hs-fs/hubfs/White-OTT-Logo-1-768x253.png?width=313&height=103&name=White-OTT-Logo-1-768x253.png)](https://www.ontimetech.com/) [![Valeo-Logo-White (1)](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Valeo-Logo-White%20(1).png?width=288&height=123&name=Valeo-Logo-White%20(1).png)](https://valeonetworks.com/)

*Return to Top*

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Lance Stone",
    "url" : "https://ontimetech.valeonetworks.com/blog/author/ulisticadmin"
  },
  "dateModified" : "2024-01-10T16:41:44.535Z",
  "datePublished" : "2018-05-10T14:18:55.000Z",
  "headline" : "New Threat Alert From The FBI – Password Spraying",
  "image" : [ "https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/ThinkstockPhotos-840534924-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://ontimetech.valeonetworks.com/blog/tech-tips/new-threat-alert-from-the-fbi-password-spraying",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://ontimetech.valeonetworks.com/hubfs/OTT%20-%20Color%20Logo.png"
    },
    "name" : "Valeo Networks"
  }
}
```