:

HACKERS LAUNCH 81M LOGIN ATTACKS ON MICROSOFT 365

SECURITY DESK2 MIN READ
WED, JUL 1, 2026

■ AI-SUMMARIZED FROM 5 SOURCES ▸ TIMELINE

Attackers conducted a large-scale password-spraying campaign against Microsoft 365 accounts, generating over 81 million login attempts within two weeks. The credential stuffing effort targeted multiple organizations in a bid to gain unauthorized access.

Security researchers detected an aggressive password-spraying operation focused on Microsoft 365 environments during a two-week window. The campaign generated more than 81 million login attempts as attackers systematically tested common passwords against user accounts across different organizations. Password spraying differs from traditional brute-force attacks. Instead of repeatedly targeting a single account, attackers try weak or commonly used passwords against many accounts simultaneously. This approach bypasses account lockout mechanisms that trigger after multiple failed attempts on one user. The campaign reflects ongoing threats to cloud-based productivity platforms. Microsoft 365—which includes Outlook, Teams, and SharePoint—remains a prime target for attackers seeking initial access to corporate networks. Compromised credentials provide footholds for data theft, ransomware deployment, and lateral movement within organizations. Security teams identified the attack through abnormal authentication patterns and IP address behavior. The breadth of the campaign suggests attackers used multiple IP addresses and distributed infrastructure to distribute login attempts across their infrastructure. Microsoft has not disclosed whether any accounts were successfully compromised through this specific campaign. However, the scale of attempts indicates attackers achieved some level of access or credential harvesting. Organizations are advised to implement multi-factor authentication (MFA) across all Microsoft 365 accounts. MFA blocks attackers even when they obtain valid credentials. Additional measures include monitoring for unusual sign-in locations, enforcing strong password policies, and reviewing conditional access rules. The incident adds to a pattern of large-scale credential attacks targeting cloud services. Previous campaigns have targeted similar platforms at comparable scales, highlighting the persistent value attackers assign to compromised cloud credentials.

■ MORE FROM THE SECURITY DESK

PeopleFinders has launched Stud or Dud, a new website that allows users to run background checks on potential romantic partners. The service uses the same public data as PeopleFinders.com.

JUST NOWIndustry Desk

Pro-Kremlin channels are distributing AI-generated videos of Ukrainian lawmakers calling for peace talks. The fabricated clips accumulated 130,000 views in two weeks, undermining public trust regardless of fact-checking efforts.

JUST NOWAI Desk

Amazon-owned Ring is deploying TAKE encryption across all cameras by default, a method designed to limit police requests for video footage while maintaining AI features like person and package detection.

JUST NOWSecurity Desk

Find My is a critical iPhone security feature that Apple recommends keeping enabled at all times. Disabling it significantly reduces your ability to locate and recover a lost or stolen device.

1H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.