
The recent news that hackers hit Microsoft 365 environments with 81 million login attempts in just two weeks proves that legacy authentication is failing. By exploiting older protocols like ROPC to bypass multi-factor authentication, attackers easily compromised dozens of organizations.
This attack highlights a systemic issue we often talk about at HYPR. Many affected businesses actually had MFA policies in place. However, because their security relied on disjointed Conditional Access policies—where MFA was only enforced for certain apps, specific admin groups, or ‘untrusted’ locations—attackers easily found the gaps.
It raises a critical question: Why does Microsoft continue to be the primary target for these automated attacks?
It’s not because Microsoft lacks strong security tools. Microsoft has invested heavily in phishing-resistant FIDO2 capabilities and Windows Hello for Business. The real issue is that large enterprises rarely operate in a pristine, ‘Microsoft-only’ bubble. The average corporate tech stack is a complex web of legacy apps, alternative identity lifecycles, and manual helpdesk recovery workflows. Attackers don’t waste time trying to break elite encryption; they scout the perimeter for the human exceptions, the misconfigurations, and the fallback methods that corporations keep active for operational convenience.
Whether it’s an 81-million-attempt password-spraying campaign or the rise of advanced Browser-in-the-Middle (BitM) Phishing-as-a-Service tools like Bluekit, the takeaway is identical. We have spent years training employees to recognize suspicious behavior, questionable URLs, and catch fraudulent prompts. But as threats scale to an automated, machine level, asking humans to act as the primary firewall is an unsustainable strategy.
We have to completely remove subjective interpretation from the identity lifecycle. True security doesn’t come from piling on more conditional rules or hoping a user spots a clever spoof.
It comes from shifting entirely to cryptographic verification, origin binding, and uniform FIDO2 passkeys across every enterprise workflow. Until organizations eliminate passwords and close the alternative backdoor paths into their environments, attackers will continue to treat the enterprise identity infrastructure as their path of least resistance.
Join our LinkedIn group Information Security Community!
















