Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 24 July 2026
RegionNew Zealand

Business in Laos? Unless you're on the ground, it's a threat.

A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to gain unauthorised access to business email infrastructure.

Attackers operating out of Laos, routing activity through infrastructure registered with the Asia Pacific Network Information Centre, have been conducting a targeted sign-in campaign against Microsoft Exchange Online. The method of attack relies on Legacy SMTP authentication — an older email protocol that bypasses many of the modern security controls organisations have in place, including multi-factor authentication. This makes it a preferred vector for threat actors who understand how enterprise email environments are constructed.

The tell-tale sign of this campaign is the volume of account lockouts it produces. When attackers use automated tooling to systematically attempt credentials against an email platform, the repeated failed attempts trigger lockout thresholds — effectively flagging the intrusion through the very security mechanisms designed to stop it. An organisation experiencing an unexpected spike in account lockouts across its Exchange Online environment should treat this as a serious indicator of an active credential attack.

The objective of gaining access to a corporate email platform such as Microsoft Exchange Online extends well beyond reading messages. A successfully compromised email account provides a foothold for business email compromise, internal phishing, data exfiltration, and lateral movement across connected services. The damage from a single breached mailbox can cascade rapidly through an organisation's broader Microsoft 365 environment, particularly where access controls have not been tightly scoped.

Organisations using Microsoft Exchange Online should treat Legacy SMTP as a high-priority exposure and move to disable it where it is not operationally required. Microsoft provides controls within the Exchange admin centre and Azure Active Directory to block legacy authentication protocols at both the tenant and per-user level. Coupling that with conditional access policies, anomalous sign-in alerting, and regular review of authentication logs will significantly reduce the attack surface this campaign is actively exploiting.

IP Intelligence
Abuse score
100/ 100High abuse
ISP (Internet Service Provider)
Asia Pacific Network Information Centre
Function:Residential/Commercial IP
Reputation:Flagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Technical advisory

How to tell if you're at risk

Organisations permitting Legacy SMTP are at risk.

How to tell if you're affected

Audit logs show high-volume failures from 183.182.99.92.

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.