Password spraying is an attack in which someone tries a small set of common passwords across many accounts. Spreading the guesses can avoid the lockout that a long sequence against one account might trigger. The attacker still needs a successful sign-in to take control.
A useful example
An organization sees a single weak password tried against hundreds of staff addresses. Most attempts fail; one account using that password succeeds. The best response is not to reset only the loudest account. Investigators check for successful sign-ins, revoke affected sessions and make sure accounts use unique strong passwords and MFA.
What an individual can do
Use a password manager to generate unique passwords, turn on MFA and report unexpected approvals to your security team. A failed-login notice does not mean your password was guessed. The
OWASP explanation describes how spraying differs from repeated guessing against one user.
Practical distinction
A failed attempt is a warning to review, not proof of entry. Successful sign-ins and new sessions determine which accounts need immediate containment.