Executive Summary
Between June 12 and 26, 2026, a sophisticated password-spraying attack targeted Microsoft 365 environments, resulting in over 81 million login attempts. The attackers utilized the Azure Command-Line Interface (CLI) to exploit valid username and password combinations from previous breaches. By leveraging the Resource Owner Password Credentials (ROPC) OAuth mechanism, they bypassed multi-factor authentication (MFA) in numerous organizations due to misconfigured Conditional Access policies. This campaign led to the compromise of 78 Microsoft accounts across 64 organizations.
This incident underscores the critical need for organizations to review and strengthen their MFA configurations and Conditional Access policies. The exploitation of ROPC highlights vulnerabilities in authentication flows that lack support for modern security measures, emphasizing the importance of comprehensive security assessments to prevent similar breaches.
Why This Matters Now
The recent surge in credential-stuffing attacks exploiting misconfigured MFA settings poses an immediate threat to organizational security. Addressing these vulnerabilities is crucial to prevent unauthorized access and potential data breaches.
Attack Path Analysis
Attackers conducted a password spraying campaign against Microsoft 365 accounts, leading to unauthorized access and data exfiltration. They exploited misconfigured Conditional Access Policies to bypass multi-factor authentication, enabling them to escalate privileges and move laterally within the environment. The attackers established command and control channels to maintain persistence and exfiltrated sensitive data, causing significant impact to the affected organizations.
Kill Chain Progression
Initial Compromise
Description
Attackers performed a password spraying attack against Microsoft 365 accounts, attempting to authenticate using commonly used passwords across multiple accounts to gain unauthorized access.
MITRE ATT&CK® Techniques
Password Spraying
Valid Accounts
Multi-Factor Authentication Request Generation
Cloud Accounts
Domain Accounts
Local Accounts
Cloud Accounts
Application Access Token
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication
Control ID: 8.3.6
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Multi-Factor Authentication
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Microsoft 365 credential stuffing attacks bypass MFA through ROPC flows, threatening financial data integrity and regulatory compliance requirements.
Health Care / Life Sciences
Password spraying campaigns targeting Azure CLI access compromise patient data security and violate HIPAA encryption and access control mandates.
Information Technology/IT
IT service providers face cascading client breaches as attackers exploit misconfigured Conditional Access Policies across managed Microsoft environments.
Government Administration
Public sector Azure deployments vulnerable to authentication bypass attacks threaten citizen data and critical infrastructure through compromised administrative access.
Sources
- Hackers target Microsoft 365 accounts with 81 million login attemptshttps://www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/Verified
- Massive Password Spray Campaign Targets Azure CLIhttps://securityboulevard.com/2026/07/massive-password-spray-campaign-targets-azure-cli/Verified
- Device-Code Phishing: The 2026 Attack That Walks Past MFA — and the CIS Hardening That Stops Ithttps://configcobra.com/blog/device-code-phishing-2026-mfa-bypass-cisVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent initial credential compromise, it would likely limit the attacker's ability to exploit compromised accounts by enforcing strict access controls.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict segmentation and access controls.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict controls on internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict egress policies.
By constraining lateral movement and data exfiltration, Aviatrix Zero Trust CNSF would likely reduce the overall impact of such incidents, limiting operational and reputational damage.
Impact at a Glance
Affected Business Functions
- Email Communications
- Cloud Resource Management
- Data Storage and Access
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive corporate emails, documents, and cloud resources.
Recommended Actions
Key Takeaways & Next Steps
- • Implement and enforce multi-factor authentication (MFA) across all applications and user groups to prevent unauthorized access.
- • Regularly review and update Conditional Access Policies to ensure they are configured to cover all authentication flows, including those used by command-line interfaces.
- • Utilize Zero Trust Segmentation to limit lateral movement by enforcing least privilege access controls within the environment.
- • Deploy Threat Detection & Anomaly Response capabilities to identify and respond to unusual authentication patterns indicative of password spraying attacks.
- • Establish Egress Security & Policy Enforcement mechanisms to monitor and control outbound data transfers, preventing unauthorized data exfiltration.



