logo

Iran-Linked “Password Spraying” Targets Municipal Response to Missile Strikes

ID: 033db2f0-91c4-5a72-a3da-88e384994ca3

STIX ID: report--033db2f0-91c4-5a72-a3da-88e384994ca3

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

### Executive Summary Check Point Research observed a coordinated Iran-linked password-spraying campaign against Microsoft 365 environments that targeted primarily municipal organizations in Israel and the UAE, peaking in three waves on March 3, 13, and 23, 2026. Attackers used rotated Tor exit nodes for broad scanning, Israel-geolocated VPN services to bypass geo-fencing once credentials were found, and then accessed/exfiltrated sensitive email data—potentially to support kinetic operations and bombing damage assessment; over 300 organizations in Israel and 25+ in the UAE were impacted. Recommended mitigations include tenant-wide MFA, conditional access/geofencing and Tor blocking, and monitoring for anomalous sign-in activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.