81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users

Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into, and some victims had multi-factor authentication switched on but not configured to cover the login route the attackers actually used.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a server rack's blinking status lights in a darkened data centre
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Between June 12 and 26, 2025, criminals made 81 million automated attempts to break into Microsoft accounts belonging to customers of security firm Huntress.
  • At least 78 accounts were successfully broken into during the two-week attack window.
  • Every attempt came from a single block of internet addresses controlled by a provider called LSHIY LLC, which has since cut off the customer responsible.
  • Attackers used a specific Microsoft login method called OAuth ROPC, explained below, to slip past some multi-factor authentication setups.
  • Many victims had multi-factor authentication turned on, configured too narrowly to block the method the criminals actually used.

Security company Huntress was watching closely when the attack began, first reported by CSO Online. A slow rise in suspicious login attempts started on June 12. Then, on June 22, the volume exploded: 30 Huntress customers were hit in a single day.

Eighty-one million attempts. Think of it as a robot trying a different password every fraction of a second, every hour, for fourteen days, against accounts belonging to real businesses. And that figure covers only Huntress customers; the actual number of compromised accounts across all Microsoft 365 users is likely higher.

This technique is called a password spray attack. Instead of hammering one account with thousands of guesses, which triggers lockouts, attackers try one or two common passwords across millions of different accounts. Boring, methodical, and effective.

How did the hackers get past multi-factor authentication?

Many targeted organisations did have multi-factor authentication, the system that requires a second verification step like a text message or app prompt before granting access. That should have stopped this. It didn't, because of a gap in configuration.

The criminals used something called the OAuth ROPC flow. OAuth is the standard that lets apps request access to your account; ROPC, which stands for Resource Owner Password Credentials, is an older part of that standard where an app hands a username and password directly to Microsoft's login server and receives back an access token, a temporary digital key, without any browser prompt and without triggering a second-factor challenge.

We first covered ROPC-based abuse on 3 July 2026, when a separate Microsoft 365 session-theft campaign showed just how many organisations leave this endpoint unguarded. The pattern here is consistent: if an authentication policy doesn't explicitly account for legacy protocol endpoints, attackers will find them.

Some organisations had set their multi-factor authentication rules to cover only certain apps, Microsoft's admin portals for example, but not every login route. The attackers came in through the Azure CLI, a text-based tool for managing Microsoft services. That path was unguarded. Others had restricted multi-factor authentication to administrators only, leaving ordinary staff accounts outside the policy's scope. Those are the accounts that were taken.

Should you worry?

If you run Microsoft 365, check that your multi-factor authentication policy applies to All Cloud Apps, not a named list. A named list has gaps, and gaps get found.

If you are an employee who received an unexpected account-activity or login alert between June 12 and 26, report it to your IT team. Change your password. ROPC abuse leaves a light footprint in logs, so a suspicious notification is worth treating seriously.

© 2026 Threat Vectr