
Last week, we witnessed 143 active sign-in attacks against Otago organisations. These attacks originated from at least 30 countries. Legacy SMTP was the dominant choice (85%), with 502 distinct accounts under fire.
Legacy SMTP is the auth method attackers rely on most against NZ organisations this week — 84.6% of all attacks used it. Legacy protocols like SMTP AUTH, IMAP and POP3 typically bypass Conditional Access and MFA policies, so organisations that haven't disabled Basic Auth remain exposed regardless of how strong their user passwords are.
The share of this week's active campaigns whose first sighting was more than 30 days ago. A high number means the attackers hitting NZ aren't opportunists — they're patient, persistent, and won't stop until they succeed or you shut the door completely. This week 98 campaigns have been grinding away for over a month.
Every source IP that we flagged as actively targeting organisations over the last 7 days. Each attack represents a distinct source, not an individual sign-in attempt. Across the sources we saw over 1700 authentication events failed, so the average attack fires at least 12 attempts every week.
The share of organisations that experienced at least one sign-in attack in the last week.
A distinct /24 subnet with multiple co-ordinating IPs sending password-spray traffic in the same window. Each subnet typically represents a compromised hosting provider, a rented botnet block, or a malicious ISP allocation. Blocking at the subnet level catches families of attacks that individual IP bans miss.
The share of user accounts that saw at least one failed sign-in, measured only against organisations that experienced attacks this week.
In NZ time that's roughly 6PM NZDT. Attackers time their campaigns to blend into legitimate traffic — spikes during NZ working hours suggest opportunistic actors piggybacking on office activity; overnight peaks (2–6 AM local) point to fully-automated infrastructure operated from other timezones.
Attackers are using pre-breached username/password combos — typically one attempt per account, spread across many mailboxes. The fix is breach-password protection (Entra ID password protection, HaveIBeenPwned integration) and MFA everywhere. This week 58 of tracked campaigns match the Credential Stuffing fingerprint (41% of everything active).

