Alex Yao Alex Yao
Back to news
Cyber Security Published on July 1, 2026

81 million Azure CLI password-spray attempts compromised 78 accounts

Huntress observed a large-scale automated password-spray campaign targeting Microsoft Azure CLI.

The attack used the deprecated OAuth ROPC flow, which sends credentials directly to the /token endpoint without prompting for MFA.

Over 81 million login attempts between June 12 and 26, 2026, originated from the IPv6 range 2a0a:d683::/32 attributed to LSHIY LLC.

The campaign compromised at least 78 accounts across 64 organizations, often by exploiting misconfigured Conditional Access policies that did not cover the ROPC flow.

Source: Huntress