SabiSys - Your Network Is Always On.
Support
Home Services
OverviewCloud & collaborationNetwork & WiFiHardwareInternet & fibreLandline & mobile telephonyMaintenanceBackup & continuity
Managed IT Cybersecurity Security check-up About Blog FAQ Contact Request your free audit
FREN
Security check-up · My IP · Speed test
+32 4 325 51 40 support@sabisys.be Office: Mon-Fri 9am-5pm · SLA clients: extended availability
← All articles Cybersecurity

81 million attempts: your old passwords have become a weapon

Between 12 and 26 June, a single group of attackers launched more than 81 million login attempts against Microsoft 365 accounts. No virus, no elaborate trap: just passwords stolen in old breaches, tried in bulk, account by account. The result: at least 78 accounts compromised across 64 organisations, sometimes despite two-factor authentication. Here is why your SME is affected, and what to check this week.

An attack with no finesse at all, and yet it works

The technique is called password spraying. Attackers gather the billions of credentials that have been circulating on the web for years, leaked from sites like LinkedIn, Dropbox and thousands of online shops. Then they try them, automatically, against the Microsoft 365 logins of thousands of businesses.

The logic is simple: if one of your staff uses the same password on their work email as on a site that was hacked five years ago, the door opens. And there is nothing exceptional about this: the specialists who spotted this campaign see, on average, close to 2,000 fraudulent login attempts per month per company. Your accounts are being tested constantly, even if no one is targeting you personally.

The detail that changes everything: MFA bypassed

The most worrying part of this campaign is not the volume, it is the login method. The attackers did not go through the usual sign-in page, but through a technical Microsoft tool (the Azure command-line interface) and an older authentication method that passes the password straight through, without ever triggering the two-factor prompt.

In other words: companies that had enabled MFA and believed they were protected were compromised all the same, because that side door was still open in their configuration. It is a lesson we often repeat with our clients: switching on a security option is not enough, you also have to close the paths that let people get around it. In Microsoft 365, this is handled with well-built conditional access policies that block legacy protocols and risky sign-in methods.

The one-sentence takeaway

Having "switched on MFA" does not mean you are protected: if the older sign-in methods are not blocked, a stolen password is still enough to get into your mailbox.

Five checks to run this week

Good news: everything that blocks this kind of attack already exists in most Microsoft 365 subscriptions. It just has to be configured. Here is where to start.

  1. Block legacy authentication. This is the side door used in this campaign. A conditional access policy that bars old protocols and sign-ins without MFA closes the route attackers use most.
  2. Check whether your addresses have leaked. Free services like haveibeenpwned.com show whether your company email addresses appear in known data breaches. If they do, the passwords involved must be changed everywhere they are reused.
  3. Require unique passwords. The real problem is not the weak password, it is the reused password. A company password manager settles the matter once and for all, with nothing for your teams to memorise.
  4. Limit access to company devices. With conditional access and Intune, only managed, compliant computers reach your data. Even with a valid password, a login from an unknown machine is refused.
  5. Monitor login attempts. Those 81 million attempts left traces in the sign-in logs of the targeted companies. Someone still has to look at them. Regular monitoring spots the campaign in progress before the account is compromised.

So what does this mean for your business?

In most cases these settings do not mean buying new licences: they mean knowing where to look in an admin console that few SMEs have time to explore. This is exactly the kind of check we carry out day to day for our clients under contract, and that we can do for you. Start with our free security check-up: eleven questions, three minutes, and you will know where you stand. Or ask straight away for a free, no-obligation audit: we check your Microsoft 365 configuration on site, including those notorious side doors.

Is your MFA really watertight?

Three minutes are enough for a first opinion.

Take the security check-up
Terms and conditions · SabiSys
Download the PDF

This site uses only technical cookies essential to its operation. No advertising cookies, no tracking.

FREN