Huntress: 81 million Azure CLI login attempts slipped past MFA

Huntress has reported an ongoing automated password spray campaign against Azure CLI authentication, with more than 81 million login attempts against its customers between 12 and 26 June. At least 78 Microsoft accounts across 64 organisations were compromised. The attackers used old username and password pairs and replayed validated credentials through the OAuth Resource Owner Password Credentials flow. Several victims had both MFA and conditional access in place, but MFA did not cover the specific flow the attackers used.

What this means for your organisation

This is not a story about missing MFA, but about MFA with gaps. An organisation that rolled out two-factor and ticked the box on its compliance overview may still have older authentication flows standing open. Combined with passwords leaked in earlier breaches, that is enough for an attacker to gain legitimate access to your cloud environment.

Berigo recommends

  • Block legacy and resource-owner authentication flows in Entra ID, and verify that conditional access actually reaches them.
  • Check MFA coverage per application and per flow, not only per user.
  • Cross-check your own accounts against known credential leaks and force resets where there are matches.
  • Alert on a burst of failed sign-ins followed by a single success from the same source.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch