
A login from China? Unless you've relocated, it's a breach probe.
A coordinated campaign is targeting Microsoft Exchange Online accounts through legacy email protocols, representing a systematic effort to compromise organisational communications infrastructure.
Attackers operating from Chinese network infrastructure, specifically through China Mobile Communications Corporation, have been conducting a sustained sign-in campaign against Microsoft Exchange Online. The activity involves repeated authentication attempts using Legacy SMTP, an older email protocol that organisations may have left enabled for compatibility with ageing systems or devices. This protocol is a known weak point in modern email security architecture.
The attack pattern centres on password-based failures, meaning the threat actors are actively submitting incorrect credentials in volume against targeted accounts. This behaviour is consistent with credential stuffing or password spraying — techniques where lists of known or commonly used passwords are systematically cycled across many accounts in an attempt to find a match. The use of Legacy SMTP is a deliberate tactical choice, as it can bypass certain modern authentication controls that would otherwise block such attempts.
Microsoft Exchange Online is a high-value target because it sits at the centre of an organisation's communications, storing email, calendar data, and contact information. A successful breach through this vector would grant an attacker persistent, quiet access to sensitive internal correspondence — a foothold that can be exploited for further intrusion, data theft, or social engineering against staff and clients.
Organisations still permitting Legacy SMTP authentication should treat this campaign as an urgent signal to review that configuration. Disabling legacy authentication protocols and enforcing modern authentication standards significantly reduces exposure to this class of attack. Monitoring for unusual sign-in failures, particularly those originating from foreign network providers, remains an essential layer of defence against systematic intrusion attempts of this nature.
How to tell if you're at risk
Organisations permitting Legacy SMTP are at risk.
How to tell if you're affected
Audit logs show high-volume failures from 111.61.176.242.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.

