- Huntress reported that the attackers made 81 million attempts to log into its customers’ accounts between June 12 and 26 — and succeeded in at least 78 cases.
- Huntress had been monitoring spray attacks for some time and noticed a sudden spike on June 22 when 30 of its customers were affected.
- The attacks all came from a single source, an IPv6 address range controlled by internet provider LSHIY LLC, according to Huntress.
- The attackers exploited previously exposed credentials and flaws in enterprises’ multi-factor authentication configurations.
- By exploiting older protocols like ROPC to bypass multi-factor authentication, attackers easily compromised dozens of organizations.
- Many affected businesses actually had MFA policies in place.
- This was possible because multi-factor authentication (MFA) had not been configured to handle the techniques deployed by the attackers.
A massive password spray attack targeting Microsoft 365 users has raised alarms as hackers made 81 million login attempts between June 12 and 26, with Huntress reporting at least 78 successful breaches. The attack originated from a single source, an IPv6 address range controlled by internet provider LSHIY LLC.3

The attackers exploited older protocols like ROP (Resource Owner Password Credentials) to bypass multi-factor authentication (MFA), which many affected organizations had in place. This highlights a significant flaw in corporate security measures, as the attack took advantage of previously exposed credentials and vulnerabilities in MFA configurations.4
Huntress had been monitoring these spray attacks and noted a gradual increase starting June 12, culminating in a sudden spike on June 22, when 30 customers were affected. The attack's success underscores the need for organizations to reassess their security protocols, as legacy authentication methods are proving inadequate against such sophisticated threats.2

Experts emphasize that true security cannot be achieved by merely adding more conditional rules or relying on users to identify phishing attempts. Instead, organizations must adopt more robust security measures to protect against evolving cyber threats.
“Microsoft 365 users have fallen victim to a significant password spray attack, with 81 million login attempts reported. Despite having multi-factor authentication policies, many organizations were compromised due to flaws in their configurations.”
