AI & ML

Massive Automated Password Attack Targets Microsoft 365 Users

Over 81 million login attempts hit Microsoft 365 accounts, with significant cracks in multi-factor authentication creating vulnerabilities for many users.

Jul 03, 2026 3 min read
Sign in to save

Scope of the Attack

An extensive automated password spray attack has recently targeted Microsoft 365 users, impacting security even for clients of the security firm Huntress. During a two-week period from June 12 to June 26, Huntress recorded an astonishing 81 million login attempts against its customers, resulting in successful breaches of at least 78 accounts. This sheer volume of attempts is indicative of a broader trend in cyberattacks, where the scale and sophistication of threats continue to increase. Those numbers are alarming, and they suggest an urgency in addressing vulnerabilities in widely used platforms like Microsoft 365.

Source of the Breach

The attack was traced back to a single source: an IPv6 address range managed by LSHIY LLC, which has since cut off access for the client using the involved IP addresses. This highlights an unsettling truth about modern cybersecurity: many breaches can often be pinpointed to specific addresses or configurations. Huntress had been tracking such attacks and noted a spike in activity starting June 22, when 30 of its clients were hit hard. While isolating an attack's origin is an important step, it often offers little solace to the companies affected. It raises questions about how a single point of failure can expose multiple businesses to risk.

How It Worked

The attackers exploited a vulnerability in the OAuth Resource Owner Password Credentials (ROPC) flow by replaying verified credentials at the /token endpoint, generating a user-delegated token on valid logins. You might wonder how attackers can bypass seemingly secure systems. A significant factor in these breaches was the lack of comprehensive multi-factor authentication (MFA) protections across user accounts. In many cases, MFA was enforced only for certain applications instead of applying universally. This type of targeted strategy can mislead organizations into a false sense of security, believing that because some protections exist, they are fully secure. But that's a dangerous misconception.

MFA Gaps

This oversight allowed attackers to bypass security measures effectively. Some organizations only required MFA for specific user groups, such as administrators, inadvertently leaving a broad range of standard users vulnerable. This creates a disparity in security across the enterprise and can lead to significant risks. In different situations, MFA was set up just for particular applications, missing avenues through which attackers could gain entry, like Azure CLI logins. What this means for companies is that a narrow focus on MFA can leave critical gaps that cybercriminals are more than happy to exploit.

As organizations look to shore up their defenses, reassessing MFA policies is not just advisable—it's essential. Companies must ensure these policies encompass all aspects of cloud security, not just a select few applications or user groups. It’s about creating a holistic security environment where every user, regardless of rank or application access, faces the same entry barriers. This won't just reduce the chances of successful intrusions but also cultivate a security-first mindset within the organization.

Implications and Future Outlook

This attack illustrates a pressing issue for IT security teams: despite advancements in technology, the implementation of sound security practices often lags behind. The numbers from Huntress are underwhelming in the context of how many accounts were actually compromised—less than one in a million login attempts led to a breach. But considering the rapidly evolving tactics of cybercriminals, even a small breach can have devastating effects on an organization's reputation and financial standing.

Here's the thing: organizations must not only implement MFA but also ensure its effectiveness. It's not enough to simply checkbox for compliance; security measures should be tested regularly and updated to account for new vulnerabilities. If you're working in this space, you know that attackers constantly adapt their techniques, making it imperative for security protocols to do the same.

And yet, having the right tools won't suffice if organizations don't foster a culture that prioritizes security awareness. Employees should be trained not just on how to log in securely but also on the broader implications of security at every level of their work. Because, let's face it, human behavior is often where breaches occur, not just technological weaknesses.

As cyber threats continue to evolve, ongoing vigilance will be the key to mitigating risks. Companies must ensure that they’re always one step ahead, addressing vulnerabilities proactively rather than reactively. Only by fostering both robust technical practices and a culture of security can organizations hope to protect themselves in an increasingly complex digital world.

Source: James Johnson · www.csoonline.com

Comments

Sign in to join the discussion.