Aller au contenu
Password spraying

One common password.
An entire team exposed.

No malware. No phishing. Just a password that's too predictable, quietly tried against your staff — and an open mailbox.

No malwareNo phishingNo alertWithin minutes
login.entreprise.local
Authentication portal
MyCompany — Sign in
Accounts identified:0 / 8

Accounts identified on LinkedIn / website

AL

Alice M.

Accountant

MA

Martin D.

Sales

JU

Julien B.

IT Manager

SO

Sophie L.

HR Director

PI

Pierre N.

Director

LA

Laura C.

Assistant

TH

Thomas R.

Backend Dev

EM

Emma V.

Marketing

Step 1 of 4

The attacker maps out your team

LinkedIn, the website, a contact email — within minutes, a list of accounts is ready.

Everything is public, nothing is protected

Work email addresses are often visible online. The attacker needs no access at all to build a target list.

The attacker

Collects 8 company email addresses in under 5 minutes.

Julien (the victim)

His day is normal. No warning signs.

Key figures

0

Common password

is enough to compromise an account

0

Alerts triggered

the attack flies under the radar

< 0

Minutes to target

emails are often public

MFA

Primary defense

blocks 99% of this type of attack