HackersWeekly
Last week, we witnessed 93 active sign-in attacks against Otago organisations. These attacks originated from at least 24 countries. Legacy SMTP was the dominant choice (80%), with 352 distinct accounts under fire.
Legacy SMTP is the auth method attackers rely on most against NZ tenants this week — 79.6% of all attacks used it. Legacy protocols like SMTP AUTH, IMAP and POP3 typically bypass Conditional Access and MFA policies, so tenants that haven't disabled Basic Auth remain exposed regardless of how strong their user passwords are.
The second-most-common auth method attackers used against NZ tenants this week. If you're blocking the top vuln (Legacy SMTP) but not this one, attackers routinely fall back to it — closing only the leading method just shifts traffic to the runner-up. Aim to disable both together.
Every source IP that we flagged as actively targeting organisations over the last 7 days. Each attack represents a distinct source, not an individual sign-in attempt. Across the sources we saw over 1700 authentication events failed, so the average attack fires at least 19 attempts every week.
Distinct M365 accounts that fielded at least one failed sign-in attempt this week. Not the same as compromised — a targeted account has been probed, not necessarily breached. High targeting counts against a small subset of accounts usually indicates a leaked address list (LinkedIn scrape, HIBP dump, or a supplier breach).
A distinct /24 subnet with multiple co-ordinating IPs sending password-spray traffic in the same window. Each subnet typically represents a compromised hosting provider, a rented botnet block, or a malicious ISP allocation. Blocking at the subnet level catches families of attacks that individual IP bans miss.
Total failed sign-in events across all tracked tenants this week. Divide by accounts targeted (352) to gauge the attacker's playbook: a low ratio suggests password spraying (many accounts, few attempts each — evading lockout); a high ratio points to credential stuffing (specific accounts, many passwords).
In NZ time that's roughly 10AM NZDT. Attackers time their campaigns to blend into legitimate traffic — spikes during NZ working hours suggest opportunistic actors piggybacking on office activity; overnight peaks (2–6 AM local) point to fully-automated infrastructure operated from other timezones.

