In Brief: Password spray campaign with 81 million login attempts compromised 78 accounts across 64 organizations, revealing widespread configuration weaknesses in Microsoft 365 environments.
Attackers conducted approximately 81 million login attempts against Microsoft 365 environments over two weeks. Security firm Huntress documented 78 compromised accounts across 64 organizations and identified configuration weaknesses in the affected systems.
The documented campaign is a password spray attack — a technique in which attackers automatically test many weak or commonly used passwords against a large pool of user accounts. The scale of 81 million attempts over two weeks indicates a large-scale operation probing far more organizations than those ultimately compromised.
For CISOs, the key takeaway is relevant: the high success rate on relatively few accounts (78 compromises from 81 million attempts) points to systematic configuration deficiencies. Typical vulnerabilities include missing or poorly enforced multi-factor authentication (MFA), weak password policies, or accounts with simplified credentials — often service accounts or test users that are overlooked in administration.
The spread across 64 organizations suggests this is not an isolated campaign targeting individual high-value organizations, but a mass operation. CISOs should audit their Microsoft 365 environments for enforced MFA across all users, strengthen password policies, and particularly review service accounts and legacy accounts that often operate outside modern security standards.
Source: www.security-insider.de · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.