Back to The Local Vocal
The Local VocalMedium
Phishing
Email
Medium risk PhishingEncountered ViaSIGN-INS 11 July 2026
RegionNew Zealand

Indian attackers are trying to get into your Microsoft Exchange Online

A maximum-abuse-score IP registered to BHARTI-AIRTEL in India is conducting widespread credential stuffing activity via Legacy SMTP, generating failed authentication attempts across many accounts.

Credential stuffing attacks conducted over Legacy SMTP represent one of the most persistent and underappreciated authentication threats facing organisations today. IP address 152.52.232.174, registered to BHARTI-AIRTEL in India, has been identified conducting this activity and carries a maximum abuse confidence score of 100 — a rating reflecting universal recognition by the global security community that this address is a source of malicious behaviour. Unlike vulnerability-based intrusion, this attack class relies entirely on harvested credential lists, which are tested methodically against authentication endpoints in an automated fashion.

Legacy SMTP is an older email authentication protocol designed before modern identity security architectures existed. Its continued presence in many environments creates a significant defensive gap: Legacy SMTP bypasses multi-factor authentication controls and falls outside the scope of conditional access policies that govern modern authentication flows. Attackers deliberately select this protocol precisely because it sidesteps these layers of protection. Organisations that have not yet disabled legacy authentication protocols are, in effect, leaving a secondary entrance to their environment that modern security tooling cannot easily monitor or restrict.

The activity recorded here is characterised by a high volume of failed authentication attempts distributed widely across accounts — a pattern entirely consistent with automated, list-based credential testing. The consistent failure reason is wrong password, confirming that no successful authentication has yet been recorded. However, the breadth of the targeting and the systematic distribution of attempts across many accounts suggests an ongoing, structured campaign designed to identify viable credentials at scale rather than focus on a single high-value target.

Organisations seeking to reduce exposure to this class of attack should treat the disablement of Legacy SMTP and IMAP authentication as a priority action. Where these protocols cannot be removed immediately, rate limiting and geo-blocking for high-risk origin regions provide meaningful interim mitigation. Multi-factor authentication should be enforced universally, and authentication audit logs should be reviewed carefully for any indication that access was achieved among the targeted accounts. Establishing ongoing alerting for spikes in legacy protocol authentication failures is a strongly recommended standing detection measure.

IP Intelligence

Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.

Abuse score100 / 100High abuse
ISPBHARTI-AIRTEL
FunctionTargeted Credential Stuffing
ReputationHigh Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

Disable legacy authentication protocols; Enforce Multi-Factor Authentication (MFA) across all accounts; Apply geo-blocking for high-risk regions; Monitor for authentication failure spikes.