
South Korean servers are knocking, but they aren't on your guest list.
A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy email protocols to force account lockouts and exploit authentication weaknesses.
Attackers operating out of South Korea, specifically through infrastructure associated with the internet service provider Jeonnambonbujang, have been conducting a sustained campaign against Microsoft Exchange Online accounts. The method of intrusion relies on Legacy SMTP — an older email communication protocol that, by design, does not support modern authentication mechanisms. This creates a significant exposure point for organisations that have not explicitly disabled legacy protocol access within their Exchange Online environment.
Legacy SMTP authentication is a known weak point in cloud email security. Unlike modern sign-in flows that enforce multi-factor authentication and conditional access policies, Legacy SMTP allows credential attempts to bypass these controls entirely. Attackers exploit this gap by submitting high volumes of login attempts against targeted accounts, operating in a manner that is both deliberate and systematic in its approach to finding valid credentials.
The observable outcome of this campaign is account lockout — a condition triggered when repeated failed authentication attempts breach the threshold set by an organisation's security policy. While account lockout is itself a protective measure, it also serves as a signal that a credential stuffing or password spraying operation is actively in progress. In some environments, persistent lockouts can disrupt legitimate users and obscure the underlying attack activity if not properly investigated.
Organisations using Microsoft Exchange Online should treat any unexplained account lockouts as a potential indicator of compromise and review authentication logs for Legacy SMTP activity. Disabling Legacy SMTP where it is not operationally required, enforcing modern authentication standards, and monitoring for sign-in attempts originating from South Korean IP ranges — particularly those associated with Jeonnambonbujang — are considered essential defensive measures against this class of attack.
Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.

