
Knock, knock, its Brazil. But don't let them in.
A coordinated campaign originating from Brazilian infrastructure is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to force lockouts and gain unauthorised access.
Attackers operating from Brazilian IP space, attributed to the internet service provider TELEFÔNICA BRASIL S.A, have been conducting a sustained sign-in campaign against Microsoft Exchange Online environments. The method of attack relies on Legacy SMTP authentication — an older mail protocol that bypasses many of the modern security controls organisations have in place, including multi-factor authentication policies applied through contemporary sign-in flows. This makes Legacy SMTP a particularly dangerous vector, as it can circumvent defences that would otherwise stop credential-based attacks cold.
The pattern observed is consistent with credential stuffing or password spraying activity, where automated tooling is used to submit high volumes of authentication attempts across multiple accounts. The inevitable result of this pressure is account lockout — a condition triggered when repeated failed sign-in attempts breach a threshold set by the platform. While lockouts indicate the perimeter held in those instances, they also serve as a signal that active, targeted effort is being directed at specific environments.
Legacy SMTP persists in many organisations not by design, but by default or oversight. Email systems, printers, line-of-business applications, and automated workflows frequently rely on it without administrators being fully aware of the exposure it creates. When Legacy SMTP remains enabled on a tenant, it effectively creates a secondary entrance that does not check the same credentials as the front door — one that threat actors from campaigns such as this actively probe and exploit.
Organisations running Microsoft Exchange Online should treat Legacy SMTP as a high-priority configuration risk. Disabling legacy authentication protocols at the tenant level, reviewing conditional access policies, and auditing service accounts that depend on older authentication methods are the most direct mitigations available. Account lockout telemetry should be reviewed not merely as an operational inconvenience, but as actionable threat intelligence indicating that an organisation's authentication surface is under active pressure.
Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.

