Last updated 2 weeks ago
Microsoft, a global technology company, suffered a large-scale password spray attack targeting its Azure command-line interface (CLI). The attack was publicly disclosed on July 1, 2026, after being detected by cybersecurity firm Huntress. The campaign compromised at least 78 Microsoft accounts out of over 81 million authentication attempts, indicating a low success rate but significant scale.
The attack originated from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167). The threat actor employed automated password spraying, a credential attack technique (MITRE ATT&CK T1110.003), against Azure CLI endpoints. The exact data compromised is not specified beyond account access, but the breach method suggests credential exposure.
No post-incident details are available in the article regarding regulatory actions, litigation, ransom payments, or remediation milestones.
Password spray attack against Azure CLI
Microsoft's Azure CLI password spray attack underscores the need for robust credential hygiene and multi-factor authentication (MFA) enforcement, especially for cloud infrastructure interfaces. The high volume of attempts (81M+) targeting a single service highlights the importance of rate limiting and anomaly detection to block automated attacks before account compromise occurs.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Continent
Country
Industry
Attack Vector
MITRE ATT&CK