Microsoft recently made a disturbing statement: almost every compromised Microsoft account is not protected by multi-factor authentication (MFA). This should be considered a good thing. The worrying thing is that only a few organizations implement this method of protection.
See also: Lockbit ransomware: FBI provides details on the operation and protection tips

In the new report Cyber Signals, the company says that just 22% of customers using its cloud-based identity platform Azure Active Directory (AAD) had implemented “strong authentication” as of December 2021. By “strong authentication,” the company means multi-factor authentication (MFA) and passwordless solutions, such as the Microsoft Authenticator app.
MFA is one of the best defenses against phishing attacks, as logging into an Office 365 account with a stolen password is not possible unless the attacker has physical access to a second factor, such as the account holder's smartphone.
Microsoft has repeatedly stressed that those who use MFA are almost certainly protected. The company revealed last year that 99% of compromised Microsoft accounts did not have multi-factor authentication enabled.
See also: Ransomware gangs carry out surgical attacks because of authorities

One potential technical hurdle is that some organizations still have Office 365 “basic authentication” enabled, which doesn’t support MFA. Microsoft’s “modern authentication” enables MFA. Microsoft will disable basic authentication by default in October 2022.
Microsoft also said it blocked billions of phishing and brute-force attacks last year. The attacks often came from government agencies, such as Nobelium, which was the group behind the SolarWinds attack.
However, some phishing attacks are successful, meaning that a significant percentage of customers who do not implement strong authentication (MFA) are vulnerable to breaches.
See also: BlackCat Ransomware: Link to BlackMatter, DarkSide Gangs
The Cyber Signals report provides a snapshot of the threats that impacted customers in 2021, as well as some insights into the threat actors using these attack techniques. As the report notes, ransomware attacks exploit default or compromised credentials. Microsoft recommends enabling MFA on all accounts, with priority given to executive, administrator, and other important user accounts.
Source: ZDNet
