Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 9 July 2026
RegionNew Zealand

More attempts from Russia? They're still trying to get in.

A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy email protocols to gain unauthorised access to organisational communications infrastructure.

Threat actors operating from Russian infrastructure, specifically through internet service provider PJSC MegaFon, have been conducting a sustained sign-in campaign against Microsoft Exchange Online accounts. The attack pattern is consistent and deliberate, indicating an organised effort rather than opportunistic probing. PJSC MegaFon is one of Russia's largest telecommunications carriers, and its infrastructure has been observed in multiple threat campaigns targeting cloud-based productivity platforms.

The method of attack relies on Legacy SMTP, an older email transmission protocol that predates modern authentication standards. Legacy SMTP is significant because it cannot support multi-factor authentication, meaning that even organisations with strong security policies may remain exposed if legacy protocol access has not been explicitly disabled within their Microsoft 365 environment. Attackers deliberately target this pathway because it bypasses many of the controls that protect modern authentication flows.

The failure reason recorded across these attempts is an incorrect password, which is characteristic of a credential stuffing or password spraying operation. In password spraying, attackers try a small number of commonly used passwords across a large number of accounts, deliberately avoiding account lockout thresholds. This technique is methodical and patient, designed to evade automated detection systems that monitor for repeated failures against a single account.

Organisations using Microsoft Exchange Online should treat Legacy SMTP as a high-risk surface that warrants immediate review. Disabling legacy authentication protocols where they are not operationally required significantly reduces exposure to this class of attack. Security teams should audit authentication logs for SMTP-based sign-in attempts originating from unfamiliar IP ranges and consider implementing conditional access policies that block legacy protocol connections by default.

IP Intelligence
Abuse score
100/ 100High abuse
ISP (Internet Service Provider)
PJSC MegaFon
Function:Residential/Commercial IP
Reputation:Flagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Technical advisory

How to tell if you're at risk

Organisations permitting Legacy SMTP are at risk.

How to tell if you're affected

Audit logs show high-volume failures from 31.173.31.66.

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.