Filed under: Cybersecurity · Cloud Account Security · July 2026
What happened Between June 12 and 26, attackers hammered Microsoft 365 accounts with more than 81 million login attempts, using username-and-password combinations leaked in old data breaches. Security firm Huntress confirmed 78 accounts compromised across 64 organizations — most of them small and mid-sized businesses. The twist: the attackers logged in through an automated back route (a legacy sign-in method called ROPC) that never shows an MFA prompt. Many victims had MFA turned on — it just wasn’t configured to cover this path.
Why it matters to your business If anyone at your company has ever reused a password that later showed up in a breach, that password may still open your Microsoft 365 door. “We have MFA” isn’t the same as “MFA covers everything” — common gaps include policies that apply only to admins, only to certain apps, only from “untrusted” locations, or that were left in report-only test mode. Once inside a mailbox, attackers read invoices, redirect payments, and phish your customers in your name.
What to do this week In the Microsoft Entra admin center (entra.microsoft.com → Protection → Conditional Access), confirm your MFA policy applies to all users and all cloud apps — not a subset — and that it’s set to “On,” not “Report-only.” Block legacy authentication with the built-in Conditional Access template. Then review Sign-in logs for waves of failed logins over the past three weeks, and reset any password that’s been reused across sites.
The bigger picture Old passwords never really die — they get sold, and eventually someone tries them on your front door. Strong account hygiene and correctly enforced MFA are the difference between a failed attempt and a hijacked mailbox. → [The First Line of Defense in Employee Data Misuse]
When did someone last actually check your MFA settings — not just confirm they exist? Book a free consult → https://micro1tech.com/contact/