
US-Based Attackers Are Trying to Get Into Your Microsoft Exchange Online
Attackers operating from high-risk US infrastructure are systematically targeting organisational credentials via Legacy SMTP, exploiting a well-known protocol gap to bypass modern authentication controls across many accounts.
A sustained credential stuffing campaign has been detected originating from IP address 64.72.74.162, registered to Zayo Bandwidth in the United States. This address carries a maximum abuse confidence score of 100, meaning it has been universally and repeatedly flagged by the global security community as a source of malicious activity. The attack vector in use is Legacy SMTP authentication — an older protocol pathway that bypasses many modern conditional access controls — a deliberate choice that signals an experienced and methodical threat actor rather than indiscriminate scanning.
The scale of the campaign, with authentication failures recorded across multiple discrete accounts, is a hallmark of credential stuffing: the systematic injection of username and password combinations sourced from prior data breaches. The attacker is not guessing randomly; they are working through a curated list, probing methodically until an entry point opens. Account lockouts have provided a temporary barrier, but they are a symptom of exposure rather than a resolution of the underlying vulnerability.
Legacy SMTP represents a significant and often underestimated attack surface for organisations running Microsoft 365 or similar cloud-hosted mail environments. Where modern authentication enforces multi-factor verification and token-based access, Legacy SMTP frequently cannot participate in those controls, creating a parallel channel that sophisticated threat actors specifically seek out. If an organisation has not yet audited which users and services still have Legacy SMTP enabled, this class of attack is a direct signal that the audit is overdue and the exposure is actively known to threat actors.
The immediate operational priority is to block the offending IP at the perimeter and mail gateway, and to review all affected accounts for signs of successful access prior to lockout. Enforce multi-factor authentication across all accounts without exception, and generate a report of all service principals and shared mailboxes still authenticating via legacy protocols. Implement a conditional access policy that blocks Legacy SMTP organisation-wide at the identity provider level — this single control eliminates the entire attack surface this campaign depends upon.
Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
Disable legacy authentication protocols; Enforce Multi-Factor Authentication (MFA) across all accounts; Apply geo-blocking for high-risk regions.

