logo

Massive Password Stealing Attack Targeting Microsoft 365 Users With 81 Million Login Attempts

ID: 33ee8dc7-bcaa-5944-bcc1-0a266f296486

STIX ID: report--33ee8dc7-bcaa-5944-bcc1-0a266f296486

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-01

Date Updated: 2026-07-02

Author: Guru Baran

...
...

Huntress tracked a large automated password-and-token spray campaign (over 81 million login attempts between 12–26 June 2026) that successfully compromised at least 78 Microsoft Entra ID accounts across 64 organizations by abusing Azure CLI and the deprecated OAuth ROPC flow to obtain tokens and bypass MFA; most attack traffic originated from IPv6 range 2a0a:d683::/32 (AS32167, LSHIY). The report identifies common Conditional Access Policy misconfigurations that enabled the abuse and recommends enforcing MFA for all users/apps/clients, restricting or blocking Azure CLI/legacy grants, tightening named locations, and continuously testing CAP behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.