Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 7 July 2026
RegionNew Zealand

Hackers in Bulgaria are actively trying to get into your mail.

A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to gain unauthorised access.

Attackers operating from Bulgaria-based infrastructure, specifically through Pronet Telecom Ltd., have been conducting a sustained campaign against Microsoft Exchange Online environments. The method of attack relies on Legacy SMTP authentication — an older email protocol that bypasses many of the modern security controls organisations have come to depend on, including multi-factor authentication. This makes it a preferred vector for adversaries who understand how to exploit gaps between legacy systems and contemporary security policy.

The attack pattern is straightforward but deliberate. Repeated sign-in attempts are submitted against target accounts using incorrect passwords, a technique consistent with credential stuffing or password spraying operations. In a credential stuffing scenario, attackers cycle through large lists of previously breached username and password combinations. In password spraying, a small number of commonly used passwords are tried across many accounts to avoid triggering lockout thresholds. Both approaches are designed to operate quietly beneath detection limits.

The risk to an organisation extends beyond a single compromised account. Microsoft Exchange Online sits at the centre of business communication, and unauthorised access can expose sensitive correspondence, enable internal phishing, facilitate business email compromise, or serve as a foothold for deeper network intrusion. The use of Legacy SMTP specifically suggests the attackers are targeting environments where modern authentication has not been fully enforced — a configuration gap that remains common across organisations of all sizes.

Organisations using Microsoft Exchange Online should treat Legacy SMTP authentication as a high-priority review item. Where it is not operationally required, disabling it removes this attack surface entirely. Security teams are advised to audit authentication logs for anomalous SMTP activity, enforce conditional access policies, and ensure that modern authentication protocols are mandated across all connected services. Proactive configuration hardening remains the most effective defence against this class of systematic, infrastructure-driven attack.

IP Intelligence
Abuse score
100/ 100High abuse
ISP (Internet Service Provider)
Pronet Telecom Ltd.
Function:Residential/Commercial IP
Reputation:Flagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Technical advisory

How to tell if you're at risk

Organisations permitting Legacy SMTP are at risk.

How to tell if you're affected

Audit logs show high-volume failures from 151.237.113.87.

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.