
Hackers in Bulgaria are actively trying to get into your mail.
A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to gain unauthorised access.
Attackers operating from Bulgaria-based infrastructure, specifically through Pronet Telecom Ltd., have been conducting a sustained campaign against Microsoft Exchange Online environments. The method of attack relies on Legacy SMTP authentication — an older email protocol that bypasses many of the modern security controls organisations have come to depend on, including multi-factor authentication. This makes it a preferred vector for adversaries who understand how to exploit gaps between legacy systems and contemporary security policy.
The attack pattern is straightforward but deliberate. Repeated sign-in attempts are submitted against target accounts using incorrect passwords, a technique consistent with credential stuffing or password spraying operations. In a credential stuffing scenario, attackers cycle through large lists of previously breached username and password combinations. In password spraying, a small number of commonly used passwords are tried across many accounts to avoid triggering lockout thresholds. Both approaches are designed to operate quietly beneath detection limits.
The risk to an organisation extends beyond a single compromised account. Microsoft Exchange Online sits at the centre of business communication, and unauthorised access can expose sensitive correspondence, enable internal phishing, facilitate business email compromise, or serve as a foothold for deeper network intrusion. The use of Legacy SMTP specifically suggests the attackers are targeting environments where modern authentication has not been fully enforced — a configuration gap that remains common across organisations of all sizes.
Organisations using Microsoft Exchange Online should treat Legacy SMTP authentication as a high-priority review item. Where it is not operationally required, disabling it removes this attack surface entirely. Security teams are advised to audit authentication logs for anomalous SMTP activity, enforce conditional access policies, and ensure that modern authentication protocols are mandated across all connected services. Proactive configuration hardening remains the most effective defence against this class of systematic, infrastructure-driven attack.
How to tell if you're at risk
Organisations permitting Legacy SMTP are at risk.
How to tell if you're affected
Audit logs show high-volume failures from 151.237.113.87.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.

