Skip to content
CloudkuCloudku

Password Spraying Targets Microsoft 365: What Advisory AA26-281A Means for You

Joint advisory AA26-281A warns of password spraying against Exchange and Office 365. A practical checklist: MFA, blocking legacy auth, separate backups.

Cloudku teamPublished

Breaking into a company’s email doesn’t always take a sophisticated exploit. Sometimes all it takes is one common password, something like “Password01”, tried against many accounts until one of them works. That technique, password spraying, is back in the spotlight after a joint warning from the FBI, CISA and several international cybersecurity agencies published on 8 October 2026.

What advisory AA26-281A covers

The advisory was co-authored by the FBI, CISA and NSA in the United States, together with the UK’s NCSC, Australia’s ASD’s ACSC, the Canadian Centre for Cyber Security, Japan’s National Police Agency and National Cybersecurity Office, New Zealand’s NCSC-NZ, and Spain’s Centro Nacional de Inteligencia.

It describes Chinese government-linked threat actors enabled by Integrity Technology Group, a for-profit company based in China with ties to its government. According to the advisory, their tactics are consistent with activity publicly tracked as Flax Typhoon, Ethereal Panda and Red Juliett. The agencies add a caveat: security vendors group and name actors in their own ways, and those groupings don’t necessarily line up one-to-one with the US government’s methodology.

The actors blend automated scanning tools, large-scale botnets and hands-on exploitation. Two of the tools stand out for Microsoft 365 customers:

  • EBurst, an open-source Python tool aimed at Microsoft Office 365 accounts. It runs password spraying and password guessing against email accounts on Exchange through a range of interfaces, including Outlook Web Access (OWA), Exchange Web Services (EWS), ActiveSync, Autodiscover and PowerShell.
  • office-cli, a command-line utility the FBI observed being used to repeatedly pull email from Outlook 365 mailboxes. Because it relies on legitimate access methods, the activity is hard to spot.

Targets include US critical infrastructure sectors and organizations across Southeast Asia, Africa and North America. In Southeast Asia, email theft victims included government bodies, law enforcement agencies, healthcare systems and religious institutions.

How password spraying works

Classic brute force throws many passwords at a single account, which quickly trips account lockout. Password spraying flips that around: a handful of common passwords are tried across many different accounts. Each account sees only a few attempts, so lockout thresholds are rarely reached. MITRE ATT&CK specifically lists internet-facing email applications such as Office 365 as common targets.

Two conditions make a Microsoft 365 account much easier to compromise:

  • No MFA. If a password is the only thing standing between an attacker and the mailbox, one correct guess is enough.
  • Legacy authentication still allowed. Older protocols such as IMAP, POP3 or SMTP with Basic authentication can’t do MFA, which gives attackers a way around it. Microsoft’s own analysis found that more than 99% of password spray attacks use legacy authentication protocols.

In Exchange Online, Microsoft has already turned off Basic authentication in every tenant for protocols such as EAS, POP, IMAP, EWS and Remote PowerShell. The exception is SMTP AUTH, which is still available for now. Microsoft has announced plans to retire Basic authentication for SMTP AUTH and has since updated that timeline, so check Microsoft’s latest official announcement for current dates. If you run Exchange on-premises, a hybrid setup, or older apps and devices that still send mail via SMTP AUTH, this gap is worth reviewing.

A security checklist for your Microsoft 365 tenant

Based on the advisory and Microsoft’s own guidance:

  1. Require MFA for everyone. The advisory recommends MFA for all services wherever possible, starting with webmail, VPN and accounts that reach critical systems. Tenants without Entra ID P1 can turn on Security Defaults at no extra cost. Microsoft says MFA combined with blocking legacy authentication stops more than 99.9% of common identity attacks.
  2. Block legacy authentication. Use Security Defaults or a Conditional Access policy. Microsoft suggests starting in Report-only mode and reviewing sign-in logs to find apps that still depend on older protocols.
  3. Use Conditional Access. It requires at least Microsoft Entra ID P1 and gives you far more control than Security Defaults. Exclude your emergency (break-glass) accounts so a misconfiguration can’t lock every admin out.
  4. Watch for unusual activity. The advisory recommends monitoring for sign-ins outside normal working hours, “impossible time and distance” logons, and connected apps in cloud accounts that can reach email and files. With Entra ID P2, Microsoft recommends a policy that requires MFA when sign-in risk is Medium or High.
  5. Apply least privilege to admins. Grant admin rights only to people who need them and review them regularly. Microsoft recommends fewer than five Global Administrators, MFA on every admin account, and dedicated admin accounts kept separate from everyday work accounts.
  6. Keep separate backups. The advisory recommends keeping multiple copies of critical data in a physically separate, segmented and secure location, and making sure those copies can’t be modified or deleted from the system where the original data lives.

Don’t forget your data protection obligations

Business email is full of personal data. Most data protection laws expect organizations to secure the personal data they handle, prevent unauthorized access, and notify affected people and regulators promptly when a breach happens, sometimes within tight deadlines. Indonesia’s Personal Data Protection Law, for example, requires written notice within 3 x 24 hours.

These laws rarely name specific technologies, but MFA, access restrictions and separate backups are reasonable technical measures. Check the rules that apply in your jurisdiction and ask your legal adviser about specific compliance questions.

How Cloudku Cyber Protection helps

MFA and legacy authentication settings live inside your own Microsoft 365 tenant. Cloudku Cyber Protection adds layers of protection and recovery on top. The following services are available on request:

  • Microsoft 365 Backup. Backs up Exchange Online, OneDrive for Business, SharePoint Online, Teams and OneNote up to six times a day, with granular restore down to a single email, file or site.
  • Entra ID Backup. Protects users, groups, policies and configuration so you can roll back to a point in time after accidental deletion, misconfiguration or an attack.
  • Email Security. Helps stop phishing, business email compromise (BEC), account takeover, spoofing and malware before they reach the inbox.
  • XDR (Extended Detection & Response). Detection and response across endpoints, email, Entra ID identities and Microsoft 365 apps.
  • MDR (Managed Detection & Response). Around-the-clock endpoint monitoring, threat triage and rapid isolation by the Acronis Threat Research Unit.

Backups are stored in an Acronis data center in Indonesia, separate from your Microsoft 365 tenant, which fits the advisory’s advice to keep copies of critical data apart from the source system.

Start with the basics

Weak passwords and legacy authentication remain an effective way in. Two questions are worth asking today: does every account in your tenant use MFA? And if one account were compromised, could you still recover your important email and files?

Learn more about Cloudku Cyber Protection or talk to our team about which services fit your organization.

Sources

  1. FBI, CISA, NSA, et al. — Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data, AA26-281A (8 October 2026)
  2. NCSC-UK — China-linked malicious actors called out by UK and international partners for targeting sensitive data globally (8 October 2026)
  3. MITRE ATT&CK — Brute Force: Password Spraying (T1110.003)
  4. Microsoft Learn — Block legacy authentication with Conditional Access
  5. Microsoft Learn — Security defaults in Microsoft Entra ID
  6. Microsoft Learn — Deprecation of Basic authentication in Exchange Online
  7. Microsoft Learn — Configure and enable risk policies (Microsoft Entra ID Protection)
  8. Microsoft Learn — Best practices for Microsoft Entra roles
  9. Microsoft Learn — Securing privileged access for hybrid and cloud deployments in Microsoft Entra ID

This article is for general information. Verify details against the cited sources before acting.

Need help applying this?

The Cloudku team can help you review your infrastructure and set up the right protection.

Talk to our team