Mass password-spray campaign uses Azure CLI and OAuth ROPC to break into Microsoft 365 accounts

Attackers made more than 81 million login attempts and successfully compromised Microsoft 365 accounts at dozens of organizations by abusing Azure CLI sign-ins. Huntress says 78 accounts at 64 organizations were breached between June 12 and 21, 2026, using password spraying and the OAuth Resource Owner Password Credentials (ROPC) flow, which can mint tokens without an interactive multi-factor authentication prompt if MFA policies are not enforced for that flow or all cloud apps. Most activity came from infrastructure tied to LSHIY.
Why it matters: Organizations using Microsoft 365 could be exposed even if they believe MFA is enabled, because gaps in conditional access or legacy auth coverage can still let attackers in. Defenders should review Azure and Entra sign-in logs, disable or restrict ROPC where possible, enforce MFA for all cloud applications and users, and reset compromised accounts.

Sources

Hackers target Microsoft 365 accounts with 81 million login attempts
Bill Toulas 2026.07.01 99% relevant
This is the same Huntress-reported campaign, adding concrete scale and timing details: 81 million login attempts from June 12 to 26, 78 compromised accounts across 64 organizations, and the specific Conditional Access misconfigurations that let Azure CLI plus OAuth ROPC bypass MFA protections.
Massive Password Spray Campaign Targeting Azure CLI
Ionut Arghire 2026.07.01 100% relevant
This article establishes a distinct ongoing credential-attack story centered on Azure CLI and OAuth ROPC abuse against Microsoft 365 tenants, not a previously tracked breach, CVE, or patch event.
← Back to all stories