
Holidaying in Brunei? Its probably not you logging in then.
A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to force lockouts and gain unauthorised access.
Attackers operating from Brunei-based infrastructure, specifically through eSpeed Broadband DSL connections, have been conducting a sustained sign-in campaign against Microsoft Exchange Online. The method being exploited is Legacy SMTP authentication — an older email protocol that, when left enabled, bypasses many of the modern security controls organisations rely on, including multi-factor authentication. This makes it a preferred vector for threat actors probing for weaknesses at scale.
The attack pattern works by repeatedly submitting credential pairs through the Legacy SMTP pathway. Because this protocol communicates differently from standard modern login interfaces, it can quietly generate a high volume of authentication attempts without triggering the same visibility that browser-based logins would. The primary observable outcome in affected environments has been account lockouts — a reliable indicator that automated tooling is being used to cycle through credential combinations at speed.
Account lockouts caused by this kind of activity carry consequences beyond a temporary disruption to email access. They signal that valid usernames have likely been enumerated, that credential lists are being tested, and that the organisation's email infrastructure is an active target. In environments where Legacy SMTP has not been explicitly disabled, the exposure is ongoing and does not resolve simply by unlocking affected accounts.
Organisations using Microsoft Exchange Online should treat Legacy SMTP as a priority configuration risk. Disabling legacy authentication protocols across the tenant, enforcing conditional access policies, and reviewing sign-in logs for anomalous SMTP authentication attempts are the immediate recommended steps. Monitoring for the eSpeed Broadband DSL network range in authentication logs may help identify the specific traffic associated with this campaign.
Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure to detect persistent probing waves.

