Back Scworld Widespread Microsoft 365 account compromise sought by Iran-linked hackers
More than 300 organizations in Israel, over 25 others in the United Arab Emirates, and a limited number of entities in the U.S., Saudi Arabia, and Europe have had their Microsoft 365 environments targeted by Iran-nexus hackers as part of a password spraying campaign that has been underway since early March, The Register reports.
Intrusions believed to assist in bombing damage assessment initiatives and kinetic operations were conducted in three waves, commencing with the widespread scanning of Microsoft accounts with weak passwords via Tor exit nodes, which is a technique commonly employed by Iranian state-backed threat operation Gray Sandstorm, according to a Check Point Research analysis. Attackers then leveraged various VPN IP addresses geolocated in Israel to log in using the stolen valid credentials and compromise emails and other sensitive information.
Such findings come as Iran-linked hacktivist operation Handala Hack leaked FBI Director Kash Patel's personal emails and breached leading U.S. medical device firm Stryker.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
