Back to The Local Vocal
Vol. 1 · A Local Vocal special
Week ending 15 August 2026

HackersWeekly

Last week, we witnessed 93 active sign-in attacks against Otago organisations. These attacks originated from at least 24 countries. Legacy SMTP was the dominant choice (80%), with 352 distinct accounts under fire.

Easiest Way In
Legacy SMTP
This week's top vuln
Why this one keeps winning

Legacy SMTP is the auth method attackers rely on most against NZ tenants this week — 79.6% of all attacks used it. Legacy protocols like SMTP AUTH, IMAP and POP3 typically bypass Conditional Access and MFA policies, so tenants that haven't disabled Basic Auth remain exposed regardless of how strong their user passwords are.

Next Easiest Way In
Modern App
Runner-up vuln
Why the runner-up matters

The second-most-common auth method attackers used against NZ tenants this week. If you're blocking the top vuln (Legacy SMTP) but not this one, attackers routinely fall back to it — closing only the leading method just shifts traffic to the runner-up. Aim to disable both together.

The World Tour
Attacks by origin country
16
US
12
IN
9
KR
7
RU
5
CN
2
SE
2
IT
2
SG
Under Siege!
93HACKERS
trying to break into your network
24 countries. Yikes!
How this is measured

Every source IP that we flagged as actively targeting organisations over the last 7 days. Each attack represents a distinct source, not an individual sign-in attempt. Across the sources we saw over 1700 authentication events failed, so the average attack fires at least 19 attempts every week.

Firing Line
352
Accounts targeted
What targeting means here

Distinct M365 accounts that fielded at least one failed sign-in attempt this week. Not the same as compromised — a targeted account has been probed, not necessarily breached. High targeting counts against a small subset of accounts usually indicates a leaked address list (LinkedIn scrape, HIBP dump, or a supplier breach).

Ghost Networks
9BOTNETS
Seen in Otago
What counts as a ghost network

A distinct /24 subnet with multiple co-ordinating IPs sending password-spray traffic in the same window. Each subnet typically represents a compromised hosting provider, a rented botnet block, or a malicious ISP allocation. Blocking at the subnet level catches families of attacks that individual IP bans miss.

Locks Rattled
1,794
Failed attempts

Total failed sign-in events across all tracked tenants this week. Divide by accounts targeted (352) to gauge the attacker's playbook: a low ratio suggests password spraying (many accounts, few attempts each — evading lockout); a high ratio points to credential stuffing (specific accounts, many passwords).

Witching Hour (UTC)
9PM
First-seen spike hour
Why timing matters

In NZ time that's roughly 10AM NZDT. Attackers time their campaigns to blend into legitimate traffic — spikes during NZ working hours suggest opportunistic actors piggybacking on office activity; overnight peaks (2–6 AM local) point to fully-automated infrastructure operated from other timezones.

First edition
Week-on-week comparisons kick in next Monday. Watch for the Rising Villain.
End of issue · next Monday, same time