Attackers conducted a large-scale password-spraying campaign against Microsoft 365 accounts, generating over 81 million login attempts within two weeks. The credential stuffing effort targeted multiple organizations in a bid to gain unauthorized access.
Security researchers detected an aggressive password-spraying operation focused on Microsoft 365 environments during a two-week window. The campaign generated more than 81 million login attempts as attackers systematically tested common passwords against user accounts across different organizations.
Password spraying differs from traditional brute-force attacks. Instead of repeatedly targeting a single account, attackers try weak or commonly used passwords against many accounts simultaneously. This approach bypasses account lockout mechanisms that trigger after multiple failed attempts on one user.
The campaign reflects ongoing threats to cloud-based productivity platforms. Microsoft 365—which includes Outlook, Teams, and SharePoint—remains a prime target for attackers seeking initial access to corporate networks. Compromised credentials provide footholds for data theft, ransomware deployment, and lateral movement within organizations.
Security teams identified the attack through abnormal authentication patterns and IP address behavior. The breadth of the campaign suggests attackers used multiple IP addresses and distributed infrastructure to distribute login attempts across their infrastructure.
Microsoft has not disclosed whether any accounts were successfully compromised through this specific campaign. However, the scale of attempts indicates attackers achieved some level of access or credential harvesting.
Organizations are advised to implement multi-factor authentication (MFA) across all Microsoft 365 accounts. MFA blocks attackers even when they obtain valid credentials. Additional measures include monitoring for unusual sign-in locations, enforcing strong password policies, and reviewing conditional access rules.
The incident adds to a pattern of large-scale credential attacks targeting cloud services. Previous campaigns have targeted similar platforms at comparable scales, highlighting the persistent value attackers assign to compromised cloud credentials.
Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.
A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.
McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.