Cybersecurity researchers have issued a stark warning regarding a "massive, ongoing, automated password spray attack" targeting Microsoft’s Azure command-line interface (CLI), which has already led to the compromise of dozens of accounts across numerous organizations. This sophisticated campaign, meticulously documented by the threat intelligence firm Huntress, leverages a deprecated OAuth flow to circumvent Conditional Access Policies (CAPs), a cornerstone of modern cloud security, exposing a critical vulnerability in enterprise security configurations. The scale and methodology of the attack underscore the persistent threat posed by credential-based assaults and the imperative for organizations to rigorously review and fortify their identity and access management (IAM) strategies, particularly concerning legacy authentication protocols.
Unveiling the Attack Vector and Scale
The malicious activity, first identified and tracked by Huntress, originates from a specific IPv6 address range (2a0a:d683::/32) under the control of LSHIY LLC (AS32167), an internet infrastructure provider. This range has served as the launchpad for an extensive campaign that, between June 12 and June 26, 2026, unleashed over 81 million login attempts against Microsoft Azure CLI instances. The sheer volume of these attempts highlights an automated and persistent effort to breach cloud environments. Alarmingly, this sustained assault successfully compromised at least 78 Microsoft accounts spread across 64 distinct organizations, demonstrating a concerning rate of success despite the prevalence of advanced security controls.
What distinguishes this particular password spray attack from many others is not merely its impressive scale, but also its insidious method of bypassing established security measures. Many of the victim organizations had implemented Conditional Access policies, which are designed to enforce robust security requirements such as multi-factor authentication (MFA) or device compliance before granting access. However, the attackers ingeniously exploited a legacy OAuth 2.0 grant type known as Resource Owner Password Credentials (ROPC) to sidestep these CAP protections. This exploitation reveals a critical "crack" in security configurations that fail to adequately account for deprecated authentication flows, allowing threat actors to slip through what would otherwise be considered robust defenses.
Understanding the Technical Underpinnings: ROPC and Conditional Access

To fully grasp the gravity of this attack, it is essential to understand the technical components involved. OAuth 2.0 is an industry-standard protocol for authorization, allowing third-party applications to obtain limited access to a user’s resources without exposing their credentials. The ROPC flow, while part of the original OAuth 2.0 specification, is now considered a legacy and insecure method. In the ROPC flow, a user directly provides their username and password to a client application, which then transmits these credentials to an authorization server to obtain an access token. This method inherently carries significant risks because it requires the client application to handle sensitive user credentials, making it vulnerable to compromise if the application itself is malicious or poorly secured. Recognizing these dangers, the ROPC flow was formally deprecated in OAuth 2.1, and security best practices strongly advise against its use.
Microsoft itself explicitly warns customers against using ROPC in its documentation, stating that it is incompatible with multi-factor authentication (MFA) and recommending more secure alternatives in most scenarios. The tech giant advises, "This flow requires a very high degree of trust in the application, and carries risks that aren’t present in other flows. You should only use this flow when more secure flows aren’t viable." This official stance underscores the inherent vulnerabilities of ROPC and highlights the critical misconfiguration or oversight that allowed attackers to weaponize it.
Conditional Access Policies (CAPs) in Azure Active Directory (now Microsoft Entra ID) are powerful tools designed to enforce organizational security requirements based on various conditions, such as user location, device state, application being accessed, and user risk level. For example, a CAP might require MFA for all access to administrative portals or block access from unmanaged devices. The fundamental flaw exposed in this campaign is that the ROPC flow does not typically route through the authorization endpoint where these CAPs are enforced. By targeting the Azure CLI application with the ROPC flow, attackers could bypass the conditional checks that would otherwise trigger MFA or deny access based on other policy criteria, effectively rendering many CAPs impotent against this specific vector.
A Chronology of Compromise
The attack unfolded over a concentrated period, demonstrating a systematic and persistent approach by the threat actors. According to Huntress, the initial phase of the credential and token spray attacks, spanning from June 12 to June 21, 2026, resulted in a steady trickle of successful logins. During this period, an average of two to four accounts were compromised daily. A notable spike occurred on June 19, when 12 user accounts, or identities, were successfully breached.
The cadence of the attack shifted dramatically on June 22. On this single day, the number of compromised identities surged to 30, impacting 23 different businesses. This significant escalation suggests either a refinement in the attack methodology, a successful targeting of particularly vulnerable organizations, or a deliberate increase in offensive efforts. The sustained nature of the attack over nearly two weeks, coupled with the varied daily success rates, paints a picture of a well-resourced and adaptive adversary. In total, the campaign led to 78 user accounts being compromised across 64 distinct organizations, indicating a broad, non-specific targeting strategy focused on credential prevalence rather than industry type.

The Attacker’s Playbook: Leveraging Pre-Existing Breaches
Huntress’s analysis suggests that the targeting in these attacks was "based entirely on password prevalence on compromised password combo lists, and is not specific to business type or industry." This indicates that the threat actors were not necessarily targeting specific high-value organizations but rather casting a wide net, leveraging vast databases of usernames and passwords obtained from previous data breaches. The strategy is simple yet effective: systematically try these leaked credentials against Azure CLI login endpoints, knowing that a certain percentage of users reuse passwords or have not rotated them after a previous breach.
The use of the ROPC vector was particularly effective because it allowed attackers to bypass MFA even in organizations that had implemented it. This was possible when MFA was not universally enforced for all client application types, or specifically not configured to account for Azure CLI ROPC logins. Huntress also pointed out that a subset of affected organizations – specifically eight businesses – had no MFA policy whatsoever, making them even more susceptible to conventional password spraying. While the ROPC bypass is a sophisticated element, the lack of basic MFA still remains a critical vulnerability for many enterprises.
The broader context of credential spraying attacks is also alarming. Huntress reported a staggering surge of over 155 times in the volume of credential spray attacks across its customer base, particularly from late May through early June. The firm observed a current mean value of approximately 1,964 failed attacks per month per Huntress-protected tenant. This data indicates that the Azure CLI campaign is not an isolated incident but rather part of a larger, systemic increase in credential-based attacks targeting cloud services, underscoring a pervasive and escalating threat landscape.
Reactions and Expert Commentary
In response to the findings, Huntress researchers emphasized the critical need for organizations to reassess their Conditional Access Policy configurations. "This attack reveals cracks in CAPs that haven’t been appropriately configured," the company stated in its blog post. "There are still potential weaknesses in how CAPs are deployed that can allow threat actors to slip through. One glaring error here is that legacy protocols like ROPC can bypass some poorly-configured CAPs entirely since they don’t go through the authorization endpoint where policies are enforced."

While Microsoft has not yet issued a specific public statement directly addressing this particular campaign (as of July 1, 2026), their existing documentation already advises against the use of ROPC. A hypothetical statement from a Microsoft spokesperson, if issued, would likely reiterate these recommendations, emphasize the importance of robust CAP configurations, and encourage customers to adhere to security best practices for identity and access management. "Microsoft continuously works to secure its platforms and educate customers on best practices," a representative might state. "While Conditional Access provides robust protection, its effectiveness relies on comprehensive configuration across all client application types. We urge all Azure users to review their authentication policies, disable deprecated flows like ROPC, and ensure MFA is enforced universally."
Independent cybersecurity analysts have also weighed in, highlighting the broader implications. Dr. Anya Sharma, a cloud security expert at the Cyber Resilience Institute, commented, "This incident is a stark reminder that even with advanced security tools like Conditional Access, the weakest link can often be found in legacy protocols or misconfigurations. Attackers are constantly probing for these seams. Organizations cannot simply deploy security solutions; they must continuously audit and update their policies to match the evolving threat landscape and deprecate insecure authentication methods proactively."
Implications and Recommendations for Fortification
The successful exploitation of the ROPC flow against Azure CLI has significant implications for cloud security strategies. Firstly, it demonstrates that reliance on default or incomplete Conditional Access Policies can create exploitable gaps, even when MFA is nominally enabled. Secondly, it highlights the enduring risk posed by deprecated authentication protocols, which often remain active in environments due to legacy application dependencies or oversight. The compromise of user accounts can lead to unauthorized access to cloud resources, data exfiltration, privilege escalation, and further lateral movement within an organization’s cloud environment, potentially causing severe financial, reputational, and operational damage.
To counter this sophisticated line of attack and bolster cloud security, Huntress and other cybersecurity experts recommend several crucial actions:
- Enforce Universal MFA and Conditional Access: Organizations must ensure that MFA is required for All Users, All Cloud Apps, and All Client App types when enabling Conditional Access Policies. This comprehensive enforcement prevents attackers from circumventing MFA by targeting specific applications or legacy flows not covered by existing policies.
- Restrict Azure CLI Access: Implement policies to restrict the Azure CLI application for non-administrative users. Access to powerful command-line tools should be granted on a need-to-know basis and subject to the strictest security controls.
- Prioritize Response by Credential Validity: In the event of an attack, organizations should prioritize incident response actions based on the validity and scope of compromised credentials, immediately revoking access and forcing password resets for affected accounts.
- Audit and Disable Legacy Protocols: Proactively identify and disable deprecated authentication flows like ROPC across all applications and services. This requires a thorough audit of all integrated applications and their authentication mechanisms to ensure no insecure pathways remain active.
- Regular Password Rotation and Strong Password Policies: While MFA is critical, strong password policies and regular rotation, especially for accounts potentially exposed in past breaches, remain fundamental security hygiene. Organizations should leverage credential monitoring services to detect if their users’ credentials appear in breach dumps.
- Continuous Security Auditing and Penetration Testing: Regularly audit Conditional Access Policies and other security configurations to ensure they are robust, up-to-date, and free from misconfigurations. Periodic penetration testing can help identify weaknesses before attackers exploit them.
- Employee Training: Educate employees about the risks of credential theft, phishing, and the importance of reporting suspicious activity. While technical controls are paramount, human vigilance remains a vital layer of defense.
This incident serves as a critical reminder that the battle for cybersecurity is a continuous and evolving one. As cloud adoption accelerates, so too does the sophistication of attacks targeting these environments. The exploitation of a deprecated OAuth flow to bypass modern Conditional Access Policies illustrates that attackers will relentlessly seek out and exploit any configuration gaps or legacy vulnerabilities. Proactive security posture management, rigorous auditing, and a commitment to deprecating insecure practices are not merely best practices but essential requirements for safeguarding digital assets in the face of persistent and ingenious cyber threats.
