2026 Microsoft Azure/M365 — LSHIY password-spray campaign bypasses MFA via ROPC (Jun)
Data compromised
At least 78 compromised Microsoft 365 user accounts across 64 customer organizations in Huntress telemetry (June 12–26, 2026); attackers reused combo-list credentials not covered by interactive MFA
Technical writeup
Huntress reported an ongoing password-spray campaign targeting Microsoft Azure CLI and Entra ID tenants between June 12 and June 26, 2026, originating primarily from IPv6 ranges tied to LSHIY LLC (AS32167). The firm observed more than 81 million failed login attempts across its customer base and confirmed 78 user-account compromises spanning 64 organizations—spiking to 30 identities on June 22 alone. Attackers validated stolen username/password pairs via the deprecated OAuth Resource Owner Password Credentials (ROPC) grant, which can mint tokens without triggering interactive MFA even when Conditional Access policies exist for browser flows. This is a platform-wide threat campaign documented by Huntress and trade press, not a Microsoft corporate data breach; Microsoft had not issued a standalone victim notification at catalog time. Treat the 78 figure as Huntress-confirmed compromised identities, not a global victim total.
Root cause
Automated password-spray against Microsoft Azure CLI / Entra ID using deprecated OAuth ROPC flow from LSHIY LLC (AS32167) IPv6 infrastructure; many victims had Conditional Access policies that did not cover ROPC