Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

littlemissmartypants

(33,588 posts)
Wed Apr 1, 2026, 04:15 PM 3 hrs ago

Iran targets M365 accounts with password-spraying attacks

Tue 31 Mar 2026 // 19:09 UTC

Suspected Iran-linked threat actors are conducting password-spraying attacks against hundreds of organizations, primarily Middle Eastern municipalities, in campaigns that security researchers believe may have been aimed at supporting bomb-damage assessment following missile strikes.

Tel Aviv-based Check Point Research on Tuesday said that the attackers used multiple source IP addresses to target numerous Microsoft 365 accounts, affecting more than 300 organizations in Israel and more than 25 in the United Arab Emirates. While most of the password spraying hit these two Middle Eastern countries, the researchers tracked similar activity from the same attacker against a "limited number" of targets in the US, Europe, and Saudi Arabia.

The attacks happened in three waves - March 3, March 13, and March 23 - and Iran-linked groups, including the Islamic Revolutionary Guard Corps' Peach Sandstorm and Gray Sandstorm, are known to use this method to gain initial access to victims' Microsoft 365 environments and steal sensitive information.

While Israel's municipal sector bore the brunt of the password-spraying attacks, other industries, including technology (63 attempts), transportation and logistics (32), healthcare (28), and manufacturing (28), were also targeted.
...
https://www.theregister.com/2026/03/31/iran_password_spraying_m365/?utm_source=dlvr.it&utm_medium=bluesky

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Iran targets M365 accounts with password-spraying attacks (Original Post) littlemissmartypants 3 hrs ago OP
Had to look it up GreatGazoo 3 hrs ago #1
If you're that stupid, you should join trump's administration. Wonder Why 1 hr ago #2

GreatGazoo

(4,612 posts)
1. Had to look it up
Wed Apr 1, 2026, 04:59 PM
3 hrs ago

password-spraying is trying the same commonly used or likely password on every known account. This avoids lock outs because each account is tried only once.

Latest Discussions»Issue Forums»Foreign Affairs»Iran targets M365 account...