Affected Systems
Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.
Exploitation Status
Active campaign confirmed. 81 million login attempts observed over two weeks. This is an ongoing credential-based attack, not a vulnerability exploit. Attackers are leveraging password spraying (low-and-slow brute force) to evade account lockout policies.
Business Impact
High risk of account compromise leading to business email compromise (BEC), data exfiltration, lateral movement, and ransomware deployment. Password spraying bypasses traditional lockout thresholds by testing common passwords across many accounts. Successful compromise grants attackers access to email, SharePoint documents, Teams conversations, and potentially admin portals. Organizations with weak password policies, no MFA, or legacy authentication enabled face elevated risk.
Urgency
🟠Within 24 hours
Recommended Actions
- Enable multi-factor authentication (MFA) for all Microsoft 365 accounts, prioritizing admin and privileged users
- Disable legacy authentication protocols in Azure AD/Entra ID to block attacks bypassing modern auth protections
- Review Azure AD sign-in logs for failed login patterns: multiple usernames from single IP, distributed low-volume failures, or login attempts from unexpected geolocations
- Implement Conditional Access policies to block or challenge logins from high-risk locations, anonymous proxies, and Tor exit nodes
- Deploy password policies that block common passwords and enforce minimum complexity; consider Azure AD Password Protection with custom banned password lists
