HomeSecurityMicrosoft: Blocked billions of brute-force and phishing attacks in 2021

Microsoft: Blocked billions of brute-force and phishing attacks in 2021

During 2021, Office 365 and Azure Active Directory (Azure AD) customers were targets of billions of phishing emails and brute-force attacks that were successfully blocked by Microsoft.

Microsoft phishing
Microsoft: Blocked billions of brute-force and phishing attacks in 2021

“From January 2021 to December 2021, we blocked more than 25.6 billion brute force authentication attacks targeting Azure AD and 35.7 billion phishing emails with Microsoft Defender for Office 365,” said Vasu Jakkal, a Microsoft executive.

See also: Custom malware allowed hackers to remain undetected within a network for 250 days

Jakkal also said that multi-factor authentication (MFA) and passwordless authentication make it much more difficult for malicious users trying to brute force attacks on their targets' Microsoft accounts.

brute force Microsoft

Even though attackers are finding new ways to attack and increasing their breach efforts, Microsoft has yet to see the vast majority of its customers interested in adopting strong authentication, including passwordless auth and MFA.

“ For example, our research shows that across all industries, only 22% of customers using Microsoft Azure Active Directory (Azure AD) have implemented strong authentication protection as of December 2021 ,” Jakkal said

See also: Microsoft: Mac malware UpdateAgent is becoming increasingly dangerous

“Passwordless auth and MFA can go a long way in preventing a variety of threats, and we are committed to educating customers about solutions like these to better protect them“.

Just last week, Microsoft warned of a multi-stage phishing campaign that leverages Azure AD to enroll devices on target networks for the purpose of distributing phishing emails. As the company explained, the attack was blocked on networks where an MFA policy was enabled in Azure AD.

Microsoft: Blocked billions of brute-force and phishing attacks in 2021
Microsoft: Blocked billions of brute-force and phishing attacks in 2021

Why does multi-factor authentication (MFA) matter?

Enabling MFA (where possible) makes it much more difficult or even impossible for attackers to carry out a successful attack and take control of user accounts.

According to a Microsoft: “Your password doesn’t matter, but MFA does!” The company’s studies have shown that it is 99.9% less likely that an account will be compromised if you use MFA.

See also: ESET: Antivirus bug allows attackers to gain Windows SYSTEM privileges

A joint study by Google, New York University, and the University of California San Diego also found that MFA can block up to 100% of automated bots, 99% of mass phishing attacks, and about 66% of targeted attacks.

CISA MFA to better protect accounts. As it explained, threat actors can easily gain access to systems and accounts that are not protected by MFA, as passwords can be easily stolen or guessed. There are many techniques to do this: phishing, social engineering, keylogging, network sniffing, malware, brute-force attacks, and credential dumping.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS