Back to The Local Vocal
The Local VocalMedium
Email
Medium riskEncountered ViaSIGN-INS 12 July 2026
RegionNew Zealand

Russian infrastructure is probing your email. Time to lock the door.

A coordinated campaign is systematically targeting Microsoft Exchange Online accounts using legacy authentication protocols to gain unauthorised access to business email infrastructure.

Attackers operating from Russian infrastructure, specifically through the internet service provider Kom lan Ltd, have been conducting a sustained sign-in campaign against Microsoft Exchange Online. The method of choice is Legacy SMTP authentication — an older email protocol that bypasses many of the modern security controls organisations rely on to protect their accounts, including multi-factor authentication.

The attack pattern involves repeated login attempts that are generating Wrong Password failures, which is a strong indicator of credential stuffing or password spraying activity. In credential stuffing, attackers use large lists of previously leaked usernames and passwords. In password spraying, a small number of common passwords are tried across a wide range of accounts. Both techniques are designed to avoid triggering account lockouts while maximising the chances of a successful breach.

Legacy SMTP is a particular point of concern because many organisations have not disabled it, often leaving it active to support older devices or third-party applications. This creates a persistent and exploitable gap — even where modern authentication has been enforced elsewhere, legacy protocols can provide attackers with an alternative path into the same mailboxes and data.

An organisation that uses Microsoft Exchange Online should treat this as an active threat requiring immediate review. Disabling Legacy SMTP where it is not operationally necessary, auditing authentication logs for anomalous sign-in attempts, and enforcing multi-factor authentication across all supported protocols are the most effective defensive steps available at this time.

IP Intelligence
Abuse score
100/ 100High abuse
ISP (Internet Service Provider)
Kom lan Ltd
Function:Residential/Commercial IP
Reputation:Flagged / Elevated Risk
Under attack
Microsoft Exchange Online
Auth method
Legacy SMTP
Legacy protocol, often lacks MFA enforcement.
Technical advisory

How to tell if you're at risk

Organisations permitting Legacy SMTP are at risk.

How to tell if you're affected

Audit logs show high-volume failures from 31.130.35.29.

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Disable Legacy Protocols: Deactivate Legacy SMTP and IMAP authentication across the tenant to close unmonitored entry points.
  • Enforce MFA: Apply mandatory Multi-Factor Authentication for all user accounts.
  • Implement Geo-Blocking: Configure Conditional Access policies to restrict authentication attempts originating from high-risk or unexpected international regions.
  • Audit Authentication Logs: Review sign-in telemetry for recurring failure patterns from the identified infrastructure.