Back to The Local Vocal
Vol. 1 · A Local Vocal special
Week ending 23 August 2026
Hacker Weekly

Last week, we witnessed 143 active sign-in attacks against Otago organisations. These attacks originated from at least 30 countries. Legacy SMTP was the dominant choice (85%), with 502 distinct accounts under fire.

Easiest Way In
Legacy SMTP
This week's top vuln
Why this one keeps winning

Legacy SMTP is the auth method attackers rely on most against NZ organisations this week — 84.6% of all attacks used it. Legacy protocols like SMTP AUTH, IMAP and POP3 typically bypass Conditional Access and MFA policies, so organisations that haven't disabled Basic Auth remain exposed regardless of how strong their user passwords are.

Devoted to the Cause
68.5%
Have been at it > 30 days
Not spray-and-pray. A siege.

The share of this week's active campaigns whose first sighting was more than 30 days ago. A high number means the attackers hitting NZ aren't opportunists — they're patient, persistent, and won't stop until they succeed or you shut the door completely. This week 98 campaigns have been grinding away for over a month.

The World Tour
Attacks by origin country
22
IN
19
CN
18
US
17
RU
6
KR
5
BR
4
MA
4
HK
Under Siege!
143HACKERS
trying to break into your network
30 countries. Yikes!
How this is measured

Every source IP that we flagged as actively targeting organisations over the last 7 days. Each attack represents a distinct source, not an individual sign-in attempt. Across the sources we saw over 1700 authentication events failed, so the average attack fires at least 12 attempts every week.

Firing Line
62.5%
Orgs Under Active Attack
How the % is calculated

The share of organisations that experienced at least one sign-in attack in the last week.

Ghost Networks
17BOTNETS
Seen in Otago
What counts as a ghost network

A distinct /24 subnet with multiple co-ordinating IPs sending password-spray traffic in the same window. Each subnet typically represents a compromised hosting provider, a rented botnet block, or a malicious ISP allocation. Blocking at the subnet level catches families of attacks that individual IP bans miss.

Users Targeted
30.3%
Of users in attacked orgs

The share of user accounts that saw at least one failed sign-in, measured only against organisations that experienced attacks this week.

Witching Hour (UTC)
5AM
First-seen spike hour
Why timing matters

In NZ time that's roughly 6PM NZDT. Attackers time their campaigns to blend into legitimate traffic — spikes during NZ working hours suggest opportunistic actors piggybacking on office activity; overnight peaks (2–6 AM local) point to fully-automated infrastructure operated from other timezones.

Top Technique
Credential Stuffing
Dominant pattern · 41% of campaigns
Credential Stuffing — the tell

Attackers are using pre-breached username/password combos — typically one attempt per account, spread across many mailboxes. The fix is breach-password protection (Entra ID password protection, HaveIBeenPwned integration) and MFA everywhere. This week 58 of tracked campaigns match the Credential Stuffing fingerprint (41% of everything active).

End of issue · next Monday, same time