Azure CLI Password Spray Attack: 78 Microsoft Accounts Compromised in 81M+ Attempts (2026)

In today's digital landscape, where cybersecurity threats loom large, a recent incident involving a password spray attack on Microsoft's Azure CLI serves as a stark reminder of the evolving nature of cyber warfare. This article delves into the intricacies of this attack, exploring the tactics employed by threat actors and the implications for organizations worldwide.

The Azure CLI Password Spray: A Massive Undertaking

The scale of this attack is nothing short of astonishing. Over a two-week period, threat actors launched over 81 million login attempts, successfully compromising at least 78 Microsoft accounts across 64 organizations. What's particularly intriguing is the use of an IPv6 address range controlled by LSHIY LLC, an internet infrastructure provider. This attack highlights the potential vulnerabilities associated with legacy systems and the need for constant vigilance.

Targeting the Weakest Link: Conditional Access Policies

One of the most fascinating aspects of this campaign is its ability to exploit Conditional Access Policies (CAPs). Despite many organizations having CAPs enabled, the attackers leveraged a deprecated OAuth flow known as Resource Owner Password Credentials (ROPC) to bypass these protections. ROPC, a legacy OAuth 2.0 grant type, allows direct credential exchange, which, when combined with poorly configured CAPs, creates a dangerous loophole.

The Role of Multi-Factor Authentication (MFA)

Microsoft's documentation explicitly warns against the use of ROPC due to its incompatibility with MFA. Yet, this attack demonstrates that even with MFA in place, organizations can still be vulnerable if their policies are not properly configured. The attackers targeted enterprises where MFA was not enforced for Azure CLI ROPC logins, showcasing the importance of a holistic approach to security.

A Surge in Credential Spray Attacks

The activity observed by Huntress indicates a significant surge in credential spray attacks, with a 155-fold increase across their customer base. This wave of attacks, which peaked in late May and early June, underscores the need for organizations to stay vigilant and adapt their security measures accordingly. The use of old, breached username/password combinations further emphasizes the importance of regular password rotation and robust security practices.

Implications and Takeaways

This attack reveals critical weaknesses in how CAPs are deployed and configured. Legacy protocols like ROPC can bypass certain CAPs, highlighting the need for organizations to stay updated with the latest security protocols. Additionally, the impact of this attack on organizations with no MFA policy at all serves as a stark reminder of the importance of basic security measures.

In conclusion, the Azure CLI password spray attack is a wake-up call for organizations to reevaluate their security strategies. By learning from this incident, businesses can fortify their defenses and stay one step ahead of threat actors. As the digital landscape continues to evolve, so too must our cybersecurity practices.

Azure CLI Password Spray Attack: 78 Microsoft Accounts Compromised in 81M+ Attempts (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Trent Wehner

Last Updated:

Views: 6639

Rating: 4.6 / 5 (76 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Trent Wehner

Birthday: 1993-03-14

Address: 872 Kevin Squares, New Codyville, AK 01785-0416

Phone: +18698800304764

Job: Senior Farming Developer

Hobby: Paintball, Calligraphy, Hunting, Flying disc, Lapidary, Rafting, Inline skating

Introduction: My name is Trent Wehner, I am a talented, brainy, zealous, light, funny, gleaming, attractive person who loves writing and wants to share my knowledge and understanding with you.