Microsoft 365 password-spray campaign drives 81M login attempts
Source headline: Hackers target Microsoft 365 accounts with 81 million login attempts
Intelligence Summary
Threat actors carried out a password-spraying campaign against Microsoft 365 sign-ins. Over roughly two weeks, the activity produced more than 81 million login attempts. The targeting focused on gaining access to user accounts rather than exploiting a specific vulnerability. This raises the risk of account takeover, credential reuse, and downstream exposure to email and document data. Organizations using Microsoft 365 should review sign-in logs, harden authentication, and reduce password-guessing success with MFA and conditional access.
Recommended Action
Inventory where Microsoft 365 runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.