logo

Iran targets M365 accounts with password-spraying attacks

ID: 50070cec-ac7d-564a-b197-fc13d8bc3c4f

STIX ID: report--50070cec-ac7d-564a-b197-fc13d8bc3c4f

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-03-31

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

**Executive summary:** Suspected Iran-linked operators conducted three waves of password-spraying against Microsoft 365 accounts targeting more than 300 organizations (mainly Israeli municipalities and some UAE targets) using Tor exit nodes, commercial VPNs, and red-team tools; researchers believe the campaign likely supported kinetic operations and bomb-damage assessment by enabling access to sensitive emails and data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.