
Hackers from the States are trying to get into your mail
A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy authentication pathways to force account lockouts across affected organisations.
Attackers operating from US-based infrastructure assigned to Comcast Cable Communications, LLC have been identified conducting a sustained sign-in campaign against Microsoft Exchange Online. The method of attack exploits Legacy SMTP authentication, an older protocol that does not support modern security controls such as multi-factor authentication. This creates a significant exposure point for any organisation that has not explicitly disabled legacy authentication within their Microsoft 365 environment.
Legacy SMTP was designed for a different era of email communication and lacks the security architecture present in modern authentication flows. Threat actors deliberately target this protocol because it allows repeated credential submission attempts without triggering the same friction that contemporary sign-in methods enforce. The result is a low-resistance pathway that can be probed at scale, often going unnoticed until meaningful damage has occurred.
The observable consequence of this activity is account lockout, which occurs when repeated failed authentication attempts breach the threshold defined by an organisation's password policy. While a locked account may appear to be a successful defensive outcome, it represents confirmation that an active attack is underway. Widespread or repeated lockouts are a reliable indicator that credential stuffing or brute-force techniques are being applied systematically against the environment.
Organisations using Microsoft Exchange Online should treat any unexplained account lockout as a signal warranting immediate investigation. Disabling legacy authentication protocols across the tenant is a foundational mitigation step that removes the attack surface being exploited in this campaign. Reviewing sign-in logs for SMTP-based authentication attempts and enforcing conditional access policies will further reduce the risk of unauthorised access through this vector.
How to tell if you're at risk
Organisations permitting Legacy SMTP are at risk.
How to tell if you're affected
Audit logs show high-volume failures from 76.132.238.43.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Immediately deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.\n* Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts, specifically targeting administrative and high-privilege identities.\n* Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.\n* Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure to detect persistent probing waves.

