
Russian infrastructure is probing your email. Time to lock the door.
A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to gain unauthorised access to business email infrastructure.
Attackers operating from Russian infrastructure, specifically through the internet service provider Kom lan Ltd, have been conducting a sustained sign-in campaign against Microsoft Exchange Online. The method of choice is Legacy SMTP authentication — an older email protocol that bypasses many of the modern security controls organisations rely on to protect their accounts, including multi-factor authentication.
The attack pattern involves repeated login attempts that are generating Wrong Password failures, which is a strong indicator of credential stuffing or password spraying activity. In credential stuffing, attackers use large lists of previously leaked usernames and passwords. In password spraying, a small number of common passwords are tried across a wide range of accounts. Both techniques are designed to avoid triggering account lockouts while maximising the chances of a successful breach.
Legacy SMTP is a particular point of concern because many organisations have not disabled it, often leaving it active to support older devices or third-party applications. This creates a persistent and exploitable gap — even where modern authentication has been enforced elsewhere, legacy protocols can provide attackers with an alternative path into the same mailboxes and data.
An organisation that uses Microsoft Exchange Online should treat this as an active threat requiring immediate review. Disabling Legacy SMTP where it is not operationally necessary, auditing authentication logs for anomalous sign-in attempts, and enforcing multi-factor authentication across all supported protocols are the most effective defensive steps available at this time.
How to tell if you're at risk
Organisations permitting Legacy SMTP are at risk.
How to tell if you're affected
Audit logs show high-volume failures from 31.130.35.29.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
- Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
- Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
- Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.

