Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 14 July 2026
RegionNew Zealand

Another US-based login attempt? It's not your team.

A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy SMTP authentication to gain unauthorised access.

Attackers based in the United States are conducting a sustained, coordinated effort to compromise Microsoft Exchange Online accounts. The campaign operates through legacy SMTP authentication — an older email protocol that many organisations have not yet disabled — making it a consistent and exploitable entry point for malicious sign-in attempts.

The attack method relies on submitting repeated incorrect passwords against targeted accounts, a technique consistent with password spraying or credential stuffing. These approaches are deliberately paced to avoid triggering standard lockout thresholds, allowing attackers to probe accounts over an extended period without immediate detection. The traffic has been traced to infrastructure operated through the internet service provider TMESISTM ESIS.

Legacy authentication protocols such as SMTP do not support modern security controls like multi-factor authentication, which is precisely why attackers favour them. Even when an organisation has enforced multi-factor authentication across its primary sign-in interfaces, legacy protocols can create a blind spot that bypasses those protections entirely — leaving accounts exposed through a channel that appears routine on the surface.

Organisations running Microsoft Exchange Online should treat legacy SMTP authentication as a critical risk surface. Disabling legacy authentication protocols where they are not operationally required, reviewing conditional access policies, and monitoring for unusual SMTP sign-in activity are essential steps in closing the gap this campaign is actively seeking to exploit.

IP Intelligence
Abuse score
100/ 100High abuse
ISP (Internet Service Provider)
TMESISTM ESIS
Function:Residential/Commercial IP
Reputation:Flagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Technical advisory

How to tell if you're at risk

Organisations permitting Legacy SMTP are at risk.

How to tell if you're affected

Audit logs show high-volume failures from 24.187.213.29.

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.