
Seoul searching? No, they're searching for your mailbox.
A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy email protocols to force lockouts and compromise organisational communications infrastructure.
Attackers operating from South Korea are conducting a targeted sign-in campaign against Microsoft Exchange Online, the cloud-based email and calendaring platform widely used across business and government organisations. The activity has been traced to infrastructure associated with Jejuteukbyeoljachido sanghasudobonbu, an internet service provider based in South Korea. The pattern of attempts is deliberate and methodical, indicating a coordinated effort rather than opportunistic probing.
The method employed in this campaign relies on Legacy SMTP — an older email transmission protocol that predates modern security controls. Legacy SMTP is significant because it does not support contemporary authentication mechanisms such as multi-factor authentication, meaning that even organisations with strong security policies in place may remain exposed if legacy protocol access has not been explicitly disabled. Attackers exploit this gap to submit authentication requests that bypass the protections applied to standard sign-in channels.
The observable outcome of these attempts is account lockout, which occurs when repeated failed authentication requests trigger the platform's built-in security thresholds. While a lockout may appear to be a defensive success, it also signals that a valid username has been identified and is being actively targeted. In a coordinated campaign of this nature, lockouts can be used strategically to map valid accounts, disrupt operations, or serve as a precursor to more targeted intrusion attempts once credentials are obtained through other means.
Organisations running Microsoft Exchange Online should treat Legacy SMTP access as a high-priority configuration risk. Where this protocol is not operationally required, it should be disabled entirely through the platform's authentication policies. Security teams are advised to review authentication logs for sign-in attempts originating from South Korean infrastructure, paying particular attention to any activity associated with the identified service provider, and to ensure that account lockout events are feeding into active monitoring and incident response workflows.
Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.

