Suspected Iranian actors attacked over 300 Israeli and more than 25 organizations in the UAE with password spraying attacks on Microsoft 365 in March 2026. The attacks came in three waves: on March 3, 13, and 23.
Target Selection
The focus was on Israeli municipal governments. Other affected sectors: technology (63 attack attempts), transport and logistics (32), healthcare (28), and manufacturing (28). Isolated targets also appeared in the USA, Europe, and Saudi Arabia.
Check Point identified a correlation between the attacked organizations and cities hit by Iranian missile strikes. The researchers conclude that the campaign was intended to support kinetic operations -- specifically: Bombing Damage Assessment (BDA), meaning damage evaluation after strikes.
Attribution
The attack patterns match known Iranian groups: Peach Sandstorm (IRGC-linked) and Gray Sandstorm, which use password spraying as their preferred method for initial access to Microsoft 365 environments.
Relevance for DACH
Direct attacks on DACH organizations were not observed in this campaign. However: Anyone maintaining business relationships with Israeli or UAE partners and sharing Microsoft 365 tenants should review their access logs.
Sources: Check Point Research Blog (31.03.2026), The Register.