
Laos Attackers Are Trying to Get Into Your Microsoft Exchange Online
Attackers from Laos are systematically targeting organisational credentials via legacy protocol gaps, probing many accounts using a method specifically designed to bypass modern security controls.
A coordinated credential stuffing campaign has been detected originating from IP address 183.182.99.92, registered to Asia Pacific Network Information Centre and geolocated to Laos. This address carries a maximum abuse confidence score of 100, confirming a well-documented history of malicious activity across the global security community. The attack is being conducted exclusively over Legacy SMTP — an older authentication protocol that deliberately bypasses many of the modern conditional access controls and multi-factor authentication policies that organisations rely upon for protection.
Legacy SMTP was designed in an era before credential theft became a widespread concern. When left active, it creates a parallel authentication channel that modern identity protection cannot reach. Threat actors specifically seek out environments where this protocol remains enabled, as it offers a reliable pathway around contemporary security investments. The deliberate selection of this method — rather than attempting standard login flows — is a strong indicator of an informed and systematic attacker rather than opportunistic noise.
The breadth of the campaign, targeting multiple accounts rather than a single user, is characteristic of credential stuffing: the automated injection of username and password combinations sourced from prior data breaches elsewhere on the internet. Account lockouts triggered during this campaign are a protective outcome, but they also represent a secondary operational disruption for legitimate users who are now unable to access their systems until the situation is resolved.
Organisations running Microsoft 365 or similar cloud-hosted mail environments should treat this incident as a direct prompt to audit Legacy SMTP enablement across all user accounts and service principals. Disabling legacy authentication protocols at the identity provider level removes this attack surface permanently. Affected accounts should be reviewed for any signs of successful access prior to lockout, and conditional access policies should be configured to block legacy authentication organisation-wide without delay.
Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
Disable legacy authentication protocols; Enforce Multi-Factor Authentication (MFA) across all accounts; Apply geo-blocking for high-risk regions.

