Citrix Breached via Password Spraying (Mar 2019): Weak Passwords at Enterprise Scale
Retrospective: this article looks back at events from March 2019, written in 2026 with the benefit of hindsight.
In March 2019, Citrix disclosed that the FBI had informed it of a breach of its internal network. The FBI's assessment, according to Citrix, was that attackers had likely used password spraying to gain an initial foothold and then worked to bypass additional layers of security.
What happened
Citrix said the attackers accessed and downloaded business documents. Later investigation indicated they had intermittent access to the network for about five months, from October 2018 to March 2019, and that personal information on current and former employees was also affected.
Why it mattered
Citrix sold remote access and virtualization products used by thousands of enterprises. A breach of a security-relevant vendor raised questions about supply-chain risk. And the initial access technique was strikingly basic: trying common passwords against many accounts.
Lessons for cloud identity
- Password spraying works against large organizations because someone always has a weak password.
- Smart lockout and banned passwords blunt the technique without locking out legitimate users.
- MFA on every externally reachable sign-in, including VPNs, remote access gateways and legacy apps.
- Watch for slow, distributed failures across accounts rather than many failures on one account.
The vendor angle
Customers of breached vendors should ask direct questions: was any customer data, code or signing infrastructure accessed? What indicators should we look for? Supply-chain risk became a much larger theme after SolarWinds in 2020, but Citrix was an early reminder.
In hindsight
Citrix later faced its own product vulnerabilities, including the widely exploited "Citrix Bleed" in 2023. Across the decade, the pattern holds: weak authentication on internet-facing systems keeps providing attackers the easiest way in.
- How to Use Entra ID Smart Lockout and Identity Protection Against Spraying How-To & Hardening
- Detecting Password Spray Attacks: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Your Security Vendor Can Be Breached — Plan for It CIO Briefings