Back to The Local Vocal
The Local VocalMedium
Phishing
Email
Medium risk PhishingEncountered ViaSIGN-INS 12 July 2026
RegionNew Zealand

South Korean Attackers Are Trying to Get Into Your Microsoft Exchange Online

Attackers operating from South Korean infrastructure are systematically targeting organisational credentials via legacy email authentication, exploiting protocol gaps that bypass modern identity controls across many accounts.

A targeted credential stuffing campaign has been recorded originating from IP address 211.228.113.27, registered to infrastructure in South Korea. The source carries a maximum abuse confidence score of 100, confirming this address has been conclusively and repeatedly identified as malicious by the international security community. The attack leveraged Legacy SMTP authentication — an older protocol pathway that circumvents many modern conditional access controls — making the method a deliberate and informed choice by the threat actor rather than an opportunistic attempt.

The systematic targeting of multiple distinct accounts, rather than a single user, indicates the attacker arrived with a prepared list of valid or likely-valid credentials sourced from prior data breaches. This is the defining characteristic of credential stuffing: structured, automated testing of stolen username and password combinations at scale. The resulting account lockouts confirm that active credentials were being tested and that the campaign was not merely scanning infrastructure, but actively probing for access.

Legacy SMTP presents a disproportionate risk relative to the volume of attempts it attracts. Organisations that have invested significantly in modern authentication controls — including multi-factor authentication and conditional access policy — may still be exposed through this older protocol pathway if it has not been explicitly disabled. Threat actors actively catalogue environments where legacy protocols remain active, treating them as preferred targets precisely because the defences are weaker.

Each account involved in this campaign requires credential rotation and a thorough review of recent mailbox activity, including sent items, forwarding rules, and any OAuth application permissions that may have been modified. Organisations should implement a conditional access policy that blocks legacy authentication at the identity provider level, eliminating this attack surface across all current and future accounts. This incident should be treated as confirmation that legacy protocol exposure is being actively identified and exploited by international threat actors.

IP Intelligence

Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.

Abuse score100 / 100High abuse
ISPJejuteukbyeoljachido sanghasudobonbu
FunctionLegacy Access Probe
ReputationHigh Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

Disable legacy authentication protocols; Enforce Multi-Factor Authentication (MFA) across all accounts; Apply geo-blocking for high-risk regions.