Return to Global Matrix
CLASSIFIED: EYES ONLY

Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations

TELEMETRY SUMMARY DECRYPTION

An Iran-linked threat actor is conducting a password-spraying campaign against over 300 Microsoft 365 organizations in Israel and the U.A.E. The operation has been executed in three waves on March 3, March 13, and March 23, 2026. This activity is assessed to be ongoing amid the current regional conflict.

This briefing snippet has been strictly truncated for global aggregation. Operators must securely establish a dedicated intelligence uplink below to access the full operational report exactly as authored by the origin network.

SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-04-07

Event Telemetry

STATUS IDENTIFIERNORMAL TRAFFIC
ORIGIN DESKCYBER
ACQUISITION TIME19:42 ZULU
AUTHORSYSTEM.AUTO[992]