Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 30 July 2026
RegionNew Zealand

Logging in from Russia? Someone is trying, and its not you.

A coordinated sign-in campaign is targeting Microsoft Exchange Online accounts through legacy authentication channels, representing a deliberate and systematic effort to compromise organisational email infrastructure.

Attackers operating from Russian infrastructure, specifically through PJSC Rostelecom — one of Russia's largest state-affiliated telecommunications providers — are conducting sustained sign-in attempts against Microsoft Exchange Online accounts. The activity bears the hallmarks of a calculated, organised operation rather than opportunistic probing, with repeated authentication requests being directed at email environments in a methodical pattern.

The method being used relies on Legacy SMTP, an older email authentication protocol that bypasses many of the modern security controls organisations have implemented, including multi-factor authentication. Legacy SMTP was designed in an era before contemporary threat landscapes existed, and its continued presence in an environment creates a meaningful gap that adversaries are actively trained to exploit. The failure reason recorded across these attempts is incorrect password entry, indicating that attackers are cycling through credential combinations in what is known as a password spray or brute-force approach.

The significance of targeting Microsoft Exchange Online specifically should not be understated. Email platforms sit at the centre of organisational operations — they carry sensitive communications, financial instructions, personnel matters, and executive correspondence. A successful breach of an Exchange Online account grants an attacker not only access to historical messages but also the ability to conduct follow-on activity such as business email compromise, internal phishing, and data exfiltration, often without immediate detection.

Organisations still permitting Legacy SMTP authentication within their Microsoft 365 environments are advised to treat this protocol as a critical exposure point. Disabling legacy authentication methods, enforcing conditional access policies, and reviewing authentication logs for anomalous sign-in attempts from foreign IP ranges are concrete steps that reduce the available attack surface. Awareness of this campaign is the first line of defence in ensuring that organisational email systems remain protected against this class of systematic, externally-driven intrusion.

IP Intelligence

Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.

Abuse score100 / 100High abuse
ISPPJSC Rostelecom
FunctionResidential/Commercial IP
ReputationFlagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts, specifically targeting administrative and high-privilege identities.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure to detect persistent probing waves.