Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 14 July 2026
RegionNew Zealand

Another US-based login attempt? It's not your team.

A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy SMTP authentication to gain unauthorised access.

Attackers based in the United States are conducting a sustained, coordinated effort to compromise Microsoft Exchange Online accounts. The campaign operates through legacy SMTP authentication — an older email protocol that many organisations have not yet disabled — making it a consistent and exploitable entry point for malicious sign-in attempts.

The attack method relies on submitting repeated incorrect passwords against targeted accounts, a technique consistent with password spraying or credential stuffing. These approaches are deliberately paced to avoid triggering standard lockout thresholds, allowing attackers to probe accounts over an extended period without immediate detection. The traffic has been traced to infrastructure operated through the internet service provider TMESISTM ESIS.

Legacy authentication protocols such as SMTP do not support modern security controls like multi-factor authentication, which is precisely why attackers favour them. Even when an organisation has enforced multi-factor authentication across its primary sign-in interfaces, legacy protocols can create a blind spot that bypasses those protections entirely — leaving accounts exposed through a channel that appears routine on the surface.

Organisations running Microsoft Exchange Online should treat legacy SMTP authentication as a critical risk surface. Disabling legacy authentication protocols where they are not operationally required, reviewing conditional access policies, and monitoring for unusual SMTP sign-in activity are essential steps in closing the gap this campaign is actively seeking to exploit.

IP Intelligence

Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.

Abuse score100 / 100High abuse
ISPTMESISTM ESIS
FunctionResidential/Commercial IP
ReputationFlagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.