
Hackers from the US are persistent. Don't let them in.
A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to gain unauthorised access to corporate email infrastructure.
Threat actors operating from US-based infrastructure assigned to Comcast Cable Communications, Inc. have been conducting a sustained sign-in campaign against Microsoft Exchange Online environments. The attack method relies on Legacy SMTP authentication — an older protocol that bypasses many modern security controls, including multi-factor authentication. This makes it a preferred vector for adversaries seeking to exploit organisations that have not fully disabled legacy authentication pathways.
The attack pattern is straightforward but effective. Repeated login attempts are submitted against target accounts using incorrect passwords, a technique consistent with credential stuffing or password spraying operations. In credential stuffing, previously leaked username and password combinations are tested at scale. In password spraying, a small set of commonly used passwords is cycled across a large number of accounts to avoid triggering lockout thresholds. Both approaches are designed to fly under the radar of standard detection tools.
The risk to an organisation that uses Microsoft Exchange Online should not be underestimated. A successful breach of a corporate email account provides an attacker with access to sensitive communications, internal data, and the ability to pivot further into connected systems. Legacy SMTP, by design, lacks the security architecture of modern authentication standards, meaning a single compromised credential can have disproportionate consequences if the protocol remains enabled.
Organisations using Microsoft Exchange Online are strongly advised to audit their authentication settings and disable Legacy SMTP where it is not operationally required. Implementing conditional access policies, enabling multi-factor authentication across all accounts, and monitoring sign-in logs for anomalous activity from unusual infrastructure are critical steps in reducing exposure to this class of attack. The systematic nature of this campaign suggests it is unlikely to be opportunistic — hardening authentication controls is a non-negotiable priority.
Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.

