The Mabna Institute Indictment (Mar 2018): Password Spraying Against Cloud Email
Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.
In March 2018, the US Department of Justice indicted nine Iranian nationals associated with the Mabna Institute for a long-running hacking campaign against universities, companies and government agencies. Prosecutors said the group had stolen around 31 terabytes of data.
How it worked
The indictment described two main techniques:
- Spear-phishing against university professors, using lures about articles and research to harvest credentials.
- Password spraying against private companies and government organizations. Instead of trying many passwords against one account (which triggers lockouts), password spraying tries a few common passwords against many accounts.
Password spraying is effective because, in any large organization, someone is using "Spring2018!" or a similar predictable password. It also avoids account lockout thresholds.
Why cloud email was a target
Cloud email services were reachable from anywhere, and many tenants still allowed legacy authentication protocols such as IMAP and POP. Those protocols did not support modern MFA, so even organizations with MFA enabled could be exposed through them.
Lessons for Microsoft 365
- Block legacy authentication. It is the most common way password spraying succeeds against tenants that have MFA.
- Ban common passwords with Entra Password Protection.
- Enforce MFA for everyone.
- Watch for many failed sign-ins spread across many accounts.
In hindsight
Microsoft eventually disabled basic authentication in Exchange Online in 2022, closing much of the gap the Mabna group exploited. Password spraying did not go away — it remained a leading technique for state actors, including the 2024 breach of Microsoft itself.