
Logging in from Tunisia? Doubt it.
A coordinated campaign originating from Tunisia is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to force unauthorised access.
Attackers operating from Tunisian-based infrastructure, specifically through ATI - Agence Tunisienne Internet, are conducting a systematic sign-in campaign against Microsoft Exchange Online environments. The activity has been identified through repeated, structured authentication attempts that follow a deliberate pattern consistent with an organised threat operation rather than opportunistic activity.
The method of attack exploits Legacy SMTP, an older mail transmission protocol that bypasses modern authentication controls such as multi-factor authentication. Legacy SMTP was designed in an era before contemporary security standards existed, and many organisations retain it for compatibility with older systems or devices. This creates a critical exposure point that adversaries actively seek out and exploit during credential-based attacks.
A defining indicator of these intrusion attempts is the resulting account lockout condition. When attackers cycle through credential combinations at volume, the repeated failed authentication requests trigger lockout policies on targeted accounts. While this demonstrates that perimeter defences are functioning, it also causes operational disruption and signals that the campaign is ongoing and persistent in nature.
Organisations running Microsoft Exchange Online should treat the presence of Legacy SMTP as an elevated risk factor requiring immediate review. Disabling legacy authentication protocols where operationally feasible, enforcing conditional access policies, and monitoring for anomalous sign-in activity originating from Tunisian IP ranges associated with ATI infrastructure are the recommended defensive priorities at this time.
How to tell if you're at risk
Organisations permitting Legacy SMTP are at risk.
How to tell if you're affected
Audit logs show high-volume failures from 196.203.231.220.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts, specifically targeting administrative and high-privilege identities.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure to detect persistent probing waves.

