## Datalyst Blog

Datalyst delivers expert managed IT services in Providence, RI. Optimize performance, secure your systems, and grow with us. Contact us today!

 [ Categories ](https://datalyst.directivesites.com/blog/categories "Categories")

 [ Tags ](https://datalyst.directivesites.com/blog/tags "Tags")

 [ Categories:  All Categories ](https://datalyst.directivesites.com/javascript:void(0); "Categories")

 Search...Suggested keywords

 [  x ](https://datalyst.directivesites.com/javascript:void(0);)

 <a class="eb-image-viewport"></a>

#  Microsoft Warns Against Password Spraying

  [Datalyst Blog](https://datalyst.directivesites.com/blog/categories/blog)   [Security](https://datalyst.directivesites.com/blog/categories/security)

  [Daniel Mathieu](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

  Friday, 03 December 2021

   [ 0 Comments ](https://datalyst.directivesites.com/blog/microsoft-warns-against-password-spraying#comments)

 [ ![Microsoft Warns Against Password Spraying](//datalyst.directivesites.com/images/easyblog_shared/December_2021/12-03-21/b2ap3_large_hackPuter_382162531_400.jpg) ](//datalyst.directivesites.com/images/easyblog_shared/December_2021/12-03-21/hackPuter_382162531_400.jpg "Microsoft Warns Against Password Spraying")

As time has passed, cybersecurity attacks have become another way some organizations and nations engage in warfare. You can argue that there is a war going on at all times in cyberspace while hackers—many of which are sponsored by government agencies—try to outdo security researchers at all turns. One such scenario sees customers in the United States and Israeli defense technology sectors becoming the target of “password spraying.”

Password spraying is a somewhat disgusting-sounding term used to describe the process of hacking into multiple accounts by spamming commonly used passwords. You can see how this can become problematic, especially considering users’ propensity for using variations of these commonly used passwords.

In the above scenario, Microsoft warns that about 250 Microsoft Office 365 customers in the aforementioned sectors were being targeted by these password spraying tactics. Microsoft has called the group performing such attacks DEV-0343, with the DEV moniker being used to showcase that the attackers are, at this time of writing, not state-sponsored. DEV-0343 is thought to originate from Iran.

Less than 20 of the targets were actually compromised, but it’s shocking that such high-profile targets would opt for such basic passwords, to say the least. It’s reported that organizations using multi-factor authentication are at much less risk compared to those who don’t. According to Microsoft, security professionals should be on the lookout for suspicious connections from Tor networks: "DEV-0343 conducts extensive password sprays emulating a Firefox browser and using IPs hosted on a Tor proxy network. They are most active between Sunday and Thursday between 7:30 AM and 8:30 PM Iran Time (04:00:00 and 17:00:00 UTC) with significant drop-offs in activity before 7:30 AM and after 8:30 PM Iran Time. They typically target dozens to hundreds of accounts within an organization, depending on the size, and enumerate each account from dozens to thousands of times. On average, between 150 and 1,000+ unique Tor proxy IP addresses are used in attacks against each organization.”

In general, your organization should be prepared to analyze its traffic for suspicious activity of any kind, particularly during off-times when nobody should be accessing your infrastructure. Furthermore, it’s critical to remember that passwords are, of course, only one part of an adequate cybersecurity strategy and that you should always strive to use multi-factor authentication when possible. Passwords are one part of this process and should be used alongside something else you have, like a secondary device or smartphone, or biometric technology.

You can count on Datalyst to stay in the loop regarding any security risk to your business and implementing solutions designed to protect your organization from any potential threats. To learn more about what we can do for your business, reach out to us at (774) 213-9701.

 [  ](https://datalyst.directivesites.com/javascript:void(0);) [  ](https://datalyst.directivesites.com/javascript:void(0);) [  ](https://datalyst.directivesites.com/javascript:void(0);)

Tags:

  [Security](https://datalyst.directivesites.com/blog/tags/security)   [Privacy](https://datalyst.directivesites.com/blog/tags/privacy)   [Authentication](https://datalyst.directivesites.com/blog/tags/authentication)

 [  Are We a Bad Influence on Our Artificially Intelli... ](https://datalyst.directivesites.com/blog/are-we-a-bad-influence-on-our-artificially-intelligent-systems)

 [  The Network Bottleneck Can Sap Productivity ](https://datalyst.directivesites.com/blog/the-network-bottleneck-can-sap-productivity)

 About the author

 [ ![Daniel Mathieu](https://datalyst.directivesites.com/images/easyblog_avatar/808_808_blogauthor.png) ](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

 [Daniel Mathieu](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

  [  ](https://datalyst.directivesites.com/javascript:void(0); "Subscribe to updates from author") [  ](https://datalyst.directivesites.com/javascript:void(0);)   [  ](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

Dan is a trusted IT advisor with a background of over 25 years in IT and continuously works on the challenges of putting the right people in place to drive business growth and customer satisfaction.

Author's recent posts

  [More posts from author](https://datalyst.directivesites.com/blog/blogger/daniel-mathieu)

 [ Friday, 31 July 2026  Are You Paying for Inactive Software? ](https://datalyst.directivesites.com/blog/are-you-paying-for-inactive-software)

 [ Wednesday, 29 July 2026  3 Reasons Why Storing Business Files Locally is Obsolete ](https://datalyst.directivesites.com/blog/3-reasons-why-storing-business-files-locally-is-obsolete)

 [ Tuesday, 28 July 2026  Combating Software Bloat and Cyber Risks ](https://datalyst.directivesites.com/newsletter-content/combating-software-bloat-and-cyber-risks)

 <a class="eb-anchor-link" data-allow-comment="1" id="comments" name="comments"> </a> Comments

  No comments made yet. Be the first to submit a comment

   **![Guest](https://datalyst.directivesites.com/media/com_easyblog/images/avatars/author.png)**   Already Registered? [Login Here](https://datalyst.directivesites.com/home/login-logout?return=aHR0cHM6Ly9kYXRhbHlzdC5kaXJlY3RpdmVzaXRlcy5jb20vYmxvZy9taWNyb3NvZnQtd2FybnMtYWdhaW5zdC1wYXNzd29yZC1zcHJheWluZw==)

 Thursday, 06 August 2026

  Subscribe to the blog (Please fill in your email address to subscribe to updates from this post.)

 **Captcha Image**
