Back to The Local Vocal
A Local Vocal special report
Week ending 4 October 2026
Hacker Weekly

Last week, we witnessed 410 active sign-in attacks against Otago organisations. These attacks originated from at least 53 countries. Legacy SMTP was the dominant choice (97%), with 1,589 distinct accounts under fire.

Easiest Way In
Legacy SMTP
This week's top vuln
Why this one keeps winning

Legacy SMTP is the auth method attackers rely on most against NZ organisations this week — 97.1% of all attacks used it. Legacy protocols like SMTP AUTH, IMAP and POP3 typically bypass Conditional Access and MFA policies, so organisations that haven't disabled Basic Auth remain exposed regardless of how strong their user passwords are.

Devoted to the Cause
76.8%
Have been at it > 30 days
Not spray-and-pray. A siege.

The share of this week's active campaigns whose first sighting was more than 30 days ago. A high number means the attackers hitting NZ aren't opportunists — they're patient, persistent, and won't stop until they succeed or you shut the door completely. This week 315 campaigns have been grinding away for over a month.

The World Tour
Attacks by origin country
79
CN
47
KR
46
US
38
RU
37
IN
31
BR
19
TW
9
SE
Under Siege!
410HACKERS
trying to break into your network
53 countries. Yikes!
How this is measured

Every source IP that we flagged as actively targeting organisations over the last 7 days. Each attack represents a distinct source, not an individual sign-in attempt. Across the sources we saw over 3600 authentication events failed, so the average attack fires at least 9 attempts every week.

Firing Line
60.7%
Orgs Under Active Attack
How the % is calculated

The share of organisations that experienced at least one sign-in attack in the last week.

Ghost Networks
33BOTNETS
Seen in Otago
What counts as a ghost network

A distinct /24 subnet with multiple co-ordinating IPs sending password-spray traffic in the same window. Each subnet typically represents a compromised hosting provider, a rented botnet block, or a malicious ISP allocation. Blocking at the subnet level catches families of attacks that individual IP bans miss.

Users Targeted
29.7%
Of users in attacked orgs

The share of user accounts that saw at least one failed sign-in, measured only against organisations that experienced attacks this week.

Witching Hour (UTC)
1AM
First-seen spike hour
Why timing matters

In NZ time that's roughly 2PM NZDT. Attackers time their campaigns to blend into legitimate traffic — spikes during NZ working hours suggest opportunistic actors piggybacking on office activity; overnight peaks (2–6 AM local) point to fully-automated infrastructure operated from other timezones.

Top Technique
Credential Stuffing
Dominant pattern · 42% of campaigns
Credential Stuffing — the tell

Attackers are using pre-breached username/password combos — typically one attempt per account, spread across many mailboxes. The fix is breach-password protection (Entra ID password protection, HaveIBeenPwned integration) and MFA everywhere. This week 174 of tracked campaigns match the Credential Stuffing fingerprint (42% of everything active).

End of issue · next Monday, same time