Moneycontrol PRO
HomeTechnologyOver 80,000 passwords compromised in a password-spraying attack; Office, Teams, Outlook and other Microsoft account details exposed

Over 80,000 passwords compromised in a password-spraying attack; Office, Teams, Outlook and other Microsoft account details exposed

A massive password-spraying attack has compromised over 80,000 Microsoft accounts, affecting Outlook, Teams, and Office. Security experts advise MFA, strong password policies, and vigilance to stay protected.

June 15, 2025 / 10:38 IST
Password spraying attack

A large-scale password-spraying attack has put over 80,000 Microsoft accounts at risk, affecting services such as Outlook, Teams, and Office 365. Security experts say the attack, which started in December 2024 and peaked in January 2025, successfully compromised numerous accounts across organisations of all sizes. The incident highlights growing cyberthreats and underscores the need for vigilance and strong protective measures.

Password-spraying attack details

Proofpoint has uncovered that the attack was orchestrated by a threat actor called UNK_SneakyStrike, who leveraged a tool known as TeamFiltration to carry it out. Password spraying involves trying a small number of frequently used password combinations across many different accounts — a tactic designed to avoid triggering alarm systems.

TeamFiltration is a sophisticated framework first made available in 2022 by a penetration tester. It lets attackers efficiently automate large-scale attacks against Microsoft Entra IDs — the directory service that underpins Outlook, Teams, and Office 365 — without quickly locking accounts due to numerous failed attempts.

Using this tool, the attacker was able to launch a dramatic attack on January 8, 2025, attempting password combinations against nearly 16,500 accounts in a single day. The attack fell silent afterwards, then resurged in small batches — a tactic designed to stay under the radar of enterprise defences.

Proofpoint, a cybersecurity firm investigating the incident, explained that the attacker routed their operations through AWS servers in different regions and abused a sacrificial Microsoft 365 account with a Business Basic license to exploit the Microsoft Teams API.

Who all are impacted?

The attack affected a vast range of organisations — from small businesses to large enterprises — across numerous sectors. Small companies were broadly targeted, with attackers attempting to compromise all their users, while in large organisations, a subset of employees were chosen at random.

This approach meant nearly 80,000 Microsoft Entra IDs were under attack, putting Outlook, Teams, Office 365, and related services at risk of unauthorised access. The attack successfully compromised numerous accounts, although the exact number of successful intrusions has not been made public.

Tips to stay protected

Security experts say multi-factor authentication, conditional access policies, and blocking suspicious IPs can help organisations stay protected. MFA adds a secondary layer of security, making password attacks less effective. Staying vigilant and maintaining strong password policies can help keep future attacks at bay.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Jun 15, 2025 10:38 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347