< Back to all clusters
[TECHNOLOGY] · United States, China · 3 sources

Microsoft 365 password‑spray campaign compromises 78 accounts across 64 organizations

Between 12 June and 26 June 2026, a large‑scale password‑spray operation generated roughly 81 million login attempts against Microsoft 365 environments and the Azure Command‑Line Interface (CLI). The campaign succeeded in compromising 78 accounts across 64 organisations.

Attackers leveraged leaked username‑password pairs and the deprecated OAuth Resource Owner Password Credentials (ROPC) flow used by Azure CLI. Because Conditional Access policies often scoped MFA to specific apps, groups or trusted locations, ROPC bypassed MFA and allowed token issuance without user interaction. Misconfigurations such as CAPs in “report‑only” mode or MFA limited to administrators left many accounts exposed.

Traffic originated from an IPv6 range (2a0a:d683::/32) registered to LSHIY LLC, a provider linked to Hong Kong, Wuhan and a New York office and associated with Chinese origin. Huntress reported the activity and unaddressed abuse reports. Recommendations include enforcing MFA for all cloud apps, disabling legacy ROPC, and tightening Conditional Access rules.