Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 24 July 2026
RegionNew Zealand

Hackers in India are at your door, and they mean business.

A coordinated sign-in campaign is systematically targeting Microsoft Exchange Online accounts using legacy email protocols to bypass modern security controls.

Attackers operating through Indian infrastructure, specifically via the internet service provider Ultranet Services Private Limited, have been conducting a sustained campaign against Microsoft Exchange Online accounts. The method of attack exploits Legacy SMTP — an older email communication protocol that many organisations retain for compatibility with ageing systems and devices. Because Legacy SMTP does not support modern authentication mechanisms, it represents a persistent weak point that threat actors actively seek out and abuse.

The attack pattern works by submitting a high volume of sign-in attempts through the Legacy SMTP channel, cycling through credential combinations in a calculated and methodical manner. This approach is not opportunistic — it reflects a deliberate targeting strategy designed to identify accounts with weak or reused passwords. The volume and consistency of these attempts are characteristic of an automated, coordinated operation rather than isolated incidents.

A key indicator of compromise in this campaign is the triggering of account lockouts. When an account becomes locked, it confirms to the attacker that the username is valid, effectively narrowing the target list. For the affected organisation, repeated lockouts across multiple accounts signal that a broader credential-stuffing or password-spraying operation is underway — not a single forgotten password or isolated user error.

Organisations still exposing Legacy SMTP to external authentication attempts face elevated risk, as this protocol cannot enforce conditional access policies, multi-factor authentication, or modern identity protections. Disabling Legacy SMTP where it is not operationally required, and auditing any remaining usage, is the most direct mitigation available. Monitoring for abnormal sign-in failure spikes — particularly those originating from Indian IP ranges associated with Ultranet Services Private Limited — should be treated as an urgent operational priority.

IP Intelligence
Abuse score
100/ 100High abuse
ISP (Internet Service Provider)
ultranet services private limited
Function:Residential/Commercial IP
Reputation:Flagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Technical advisory

How to tell if you're at risk

Organisations permitting Legacy SMTP are at risk.

How to tell if you're affected

Audit logs show high-volume failures from 103.55.89.5.

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.