Protect.Computer
NEWS

81 Million Login Attempts Hit Microsoft 365 Accounts

· 1 min read · Got hacked Identity theft
81 Million Login Attempts Hit Microsoft 365 Accounts

A threat actor bombarded Microsoft 365 accounts with more than 81 million automated login attempts over just two weeks, from June 12 to June 26. The attackers weren’t guessing random passwords — they were recycling email-and-password combinations stolen in previous data breaches, a technique called password spraying. By testing those leaked credentials against Microsoft’s login systems, they successfully broke into 78 accounts spread across 64 different organizations.

The attack worked in part because the criminals used a technical back door: Azure’s command-line interface, which in some configurations can bypass multi-factor authentication (MFA). Organizations that had gaps in their MFA setup — such as applying it only to certain apps or only to administrators — were the ones caught out. If your Microsoft 365 account has MFA properly enabled for everything, the attack wouldn’t have worked against you.

How to check if you’re affected

Affected products include Microsoft 365 accounts where MFA is not turned on for every application and every user. Here’s what to check:

  1. Sign in to your Microsoft account at account.microsoft.com and go to Security → Advanced security options. Make sure two-step verification is turned on.
  2. If your organization manages your account, ask your IT contact to confirm that MFA applies to all cloud apps — not just a subset.
  3. Check your Sign-in activity (under Security) for any unfamiliar locations or devices from mid-June onward. If you see something suspicious, change your password immediately and notify your IT team.

Sources

Related reading