Hackers Fired 81 Million Login Attempts at Microsoft 365 — Some Worked

Think your MFA is enough? Think again.

Huntress spotted a password-spraying campaign targeting Microsoft 365 that generated over 81 million login attempts in just two weeks. Between June 12 and 26, a threat actor hammered Azure CLI endpoints with credential pairs leaked from previous breaches.

When they found a valid combo, they authenticated via ROPC — Resource Owner Password Credentials. That’s an OAuth flow that doesn’t support MFA. It just sends the password straight to the token endpoint. No interactive prompt. No second factor.

Result: 78 compromised accounts across 64 organizations.

Huntress points out the real problem here wasn’t the attack itself. It was configuration gaps. Many victims had MFA policies, but they weren’t covering this flow. Common misconfigurations included: MFA applied to specific apps only instead of All Cloud Apps, MFA enforced only for admins, MFA required only from untrusted locations (which let trusted-looking IPs through), and policies set to report-only mode — never actually enforced.

Some orgs had no MFA policy at all.

The campaign came from an IPv6 range owned by LSHIY LLC (AS32167). Huntress reported it through their abuse portal. No response yet.

Overall, password-spraying is up 155-fold. Organizations are now seeing an average of 1,964 failed login attempts per tenant per month.

Check your Conditional Access policies. If ROPC isn’t blocked, your MFA might as well not exist.

References