Pandorex
Security

Iran Coordinates Password Spraying Against 300+ Organizations in Israel and UAE

Published Pandorex Redaktion·5 min read
—

Suspected Iranian actors attacked over 300 Israeli and more than 25 organizations in the UAE with password spraying attacks on Microsoft 365 in March 2026. The attacks came in three waves: on March 3, 13, and 23.

Target Selection

The focus was on Israeli municipal governments. Other affected sectors: technology (63 attack attempts), transport and logistics (32), healthcare (28), and manufacturing (28). Isolated targets also appeared in the USA, Europe, and Saudi Arabia.

Check Point identified a correlation between the attacked organizations and cities hit by Iranian missile strikes. The researchers conclude that the campaign was intended to support kinetic operations -- specifically: Bombing Damage Assessment (BDA), meaning damage evaluation after strikes.

Attribution

The attack patterns match known Iranian groups: Peach Sandstorm (IRGC-linked) and Gray Sandstorm, which use password spraying as their preferred method for initial access to Microsoft 365 environments.

Relevance for DACH

Direct attacks on DACH organizations were not observed in this campaign. However: Anyone maintaining business relationships with Israeli or UAE partners and sharing Microsoft 365 tenants should review their access logs.

Sources: Check Point Research Blog (31.03.2026), The Register.

Comments

Sign in to write a comment.

Swipe up
Next Article

EU Commission Hacked: Attackers Breached AWS Cloud of Europa Websites

Security