Their multi-factor was switched on. Attackers got into Microsoft 365 anyway
Between 12 and 26 June a password-spraying operation made more than 81 million sign-in attempts against Microsoft 365 accounts and got into 78 of them, across 64 businesses. The figures come from security firm Huntress, which watches Microsoft 365 accounts for its customers, and were picked up independently by several security outlets.
The number that matters is this one: 55 of those 78 accounts were covered by a policy requiring multi-factor authentication when they were broken into.
The attackers did not defeat multi-factor. They walked around it. Rather than using the normal sign-in screen, they authenticated through a Microsoft command-line tool using an old sign-in method that hands a username and password straight to Microsoft and never displays the page where the second factor gets requested. If nothing tells Microsoft to refuse that route, the door opens without anyone being asked for a code.
Who this affects
Anybody on Microsoft 365 whose answer to “are your accounts protected?” is “yes, we turned on multi-factor”. That answer is now incomplete, and it is the most common answer we hear.
Huntress found five ways the protection had been left with a gap in it, and none of them look wrong at a glance. Some businesses had required a second factor for the admin portals but not for every application, so the older route was never covered. Some had applied the rule to certain groups of staff, and the account that got taken was in neither. Some had exceptions for trusted locations that the attackers’ addresses happened to fall inside. Two had built the policy properly and left it in report-only mode, where it watches and records but never actually stops anyone. Eight accounts had no policy over them at all.
What to check in your tenant
- Check the policy covers all cloud apps, not a chosen few. This is the gap that let the June campaign through, and it is the first thing to look at.
- Check it covers all users, with no leftover exclusions. Exemptions get added for a reason – a director travelling, a shared mailbox – and then outlive it.
- Turn off the old sign-in routes. Legacy authentication and the command-line method used here have no place in most small businesses and can be blocked outright.
- Make sure the policy is actually enforced. Report-only is for testing. If it has been sitting in report-only since it was set up, it has never stopped a single sign-in.
- Look at trusted-location exceptions. “Anyone in the UK is fine” is not much of a rule when credentials are traded openly and attackers rent addresses anywhere they like.
Worth twenty minutes of somebody’s time
None of the above is exotic, and none of it costs anything to fix – it is configuration, not products. But it does need somebody to sit down with the settings and check them properly against how your business actually works, which is not the same as switching multi-factor on and moving to the next job.
If you would like that checked, or you simply want to know whether “we have multi-factor” is true in the way you think it is, that is exactly what our Microsoft 365 protection and Office 365 support are for – watched round the clock, so a sign-in from somewhere odd is spotted rather than logged.
Call us on 01202 237 273 or book a call.