Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 30 July 2026
RegionNew Zealand

Logging in from Tunisia? Doubt it.

A coordinated campaign originating from Tunisia is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to force unauthorised access.

Attackers operating from Tunisian-based infrastructure, specifically through ATI - Agence Tunisienne Internet, are conducting a systematic sign-in campaign against Microsoft Exchange Online environments. The activity has been identified through repeated, structured authentication attempts that follow a deliberate pattern consistent with an organised threat operation rather than opportunistic activity.

The method of attack exploits Legacy SMTP, an older mail transmission protocol that bypasses modern authentication controls such as multi-factor authentication. Legacy SMTP was designed in an era before contemporary security standards existed, and many organisations retain it for compatibility with older systems or devices. This creates a critical exposure point that adversaries actively seek out and exploit during credential-based attacks.

A defining indicator of these intrusion attempts is the resulting account lockout condition. When attackers cycle through credential combinations at volume, the repeated failed authentication requests trigger lockout policies on targeted accounts. While this demonstrates that perimeter defences are functioning, it also causes operational disruption and signals that the campaign is ongoing and persistent in nature.

Organisations running Microsoft Exchange Online should treat the presence of Legacy SMTP as an elevated risk factor requiring immediate review. Disabling legacy authentication protocols where operationally feasible, enforcing conditional access policies, and monitoring for anomalous sign-in activity originating from Tunisian IP ranges associated with ATI infrastructure are the recommended defensive priorities at this time.

IP Intelligence
Abuse score
100/ 100High abuse
ISP (Internet Service Provider)
ATI - Agence Tunisienne Internet
Function:Residential/Commercial IP
Reputation:Flagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Technical advisory

How to tell if you're at risk

Organisations permitting Legacy SMTP are at risk.

How to tell if you're affected

Audit logs show high-volume failures from 196.203.231.220.

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts, specifically targeting administrative and high-privilege identities.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure to detect persistent probing waves.