THE ECHO
One story. Gone deep.
Somebody asked you this year. An insurance renewal, a customer's security questionnaire, an auditor working down a control list. Do you have multi-factor authentication?
You said yes. It was true.
Here is what happened in June to a few dozen companies that gave the same answer.
Over roughly two weeks in the middle of the month, Huntress watched one campaign throw more than 81 million login attempts at Microsoft cloud accounts. Seventy-eight accounts were taken over. Many of the businesses behind them had MFA. Not on paper. Enforced through a Conditional Access Policy that somebody sat down and configured on purpose.
The attackers never triggered a prompt. Not because they beat one. Because the door they came through doesn't have one.
There's an old sign-in path that the OAuth standard still carries, and that its newest version deprecates. It takes a username and a password and hands them straight over. No second step. No approval on anybody's phone. The flow predates the idea that there should be one. The Conditional Access Policy covered the front door. It didn't cover that path.
So the password was the whole test. And there is an entire category of software whose only job is answering a password test a few million times an hour until one comes back right.
Here's a separate number, and it belongs in its own sentence because the scope is different. Across the first half of 2026, Huntress measured password spraying up 155 times over. Not in that campaign. Overall.
Come back to the questionnaire.
Everybody who asks about your identity controls asks the same thing. The insurer asks whether MFA is enabled. The customer's vendor form asks whether it's enforced on administrative accounts. The SOC 2 control asks whether it's configured and whether you can evidence it. Three parties, three formats, one question with a yes-or-no answer.
Not one of them asks whether anything can still authenticate without it.
Those are two different questions, and only one of them would have mattered in June. The first one can be answered off a settings page. The second one takes somebody going and finding out.
Yes describes something you bought and switched on. That's real, and it's worth having. It just isn't the same as knowing where your identity boundary actually runs.
That second answer isn't on a control list. It's in the paths nobody wrote down. The legacy protocol still enabled on your tenant because turning it off might break something. The exemption somebody added during a migration two years ago and never took back out. The integration that signs in with a fixed credential, because a fixed credential is all it supports.
None of that shows up as a no on a form. All of it was in scope in June.
Here's why that list exists. MFA arrived as a project. It had a start date, a rollout plan, a completion email, and then it was done. Nobody scheduled the part where you go back and ask what didn't get covered, because the project closed, the box got checked, and the form said yes.
The next form is already in your inbox, and it's going to ask the first question. You'll answer it honestly, and you'll be right.
Somebody should be asking the second one. Nobody is going to send you a form for it.
SIGNAL CHECK
What else matters this week.
It Republishes Itself
Your software vendors build their products out of other people's code. Somebody weaponized that this month.
A self-replicating worm called ChainDrop has poisoned more than 1,300 pieces of that shared code, downloaded around two billion times a month between them. Code associated with Deliveroo, Picsart and ServiceTitan is on the list. BleepingComputer, SecurityWeek and The Register have all been on it since mid-August.
It started with one person's GitHub account.
A poisoned piece carries two files. The first runs automatically during the build, before the build has even finished, so it has already run by the time anyone could look at it. The second steals credentials. The worm then republishes poisoned copies of everything those stolen credentials can touch, and uses the stolen account to keep going. On August 4 it produced 2,212 poisoned versions in under four hours.
You never run that build. Your vendors do, and whatever they built ships to you.
The guidance for anyone caught in it is not a patch. Rebuild from clean backups or from scratch, rotate every credential in the environment, go through the logs and the code. That's a week for a small engineering team. Worth asking your vendors whether they had one.
The Caller ID Says It's Your Helpdesk
An extortion crew tracked as UNC6671 has built its entire intrusion model around a phone call. SecurityWeek and Dark Reading both covered the group this month, after a rebrand.
They call your IT helpdesk and spoof the number, so the caller ID shows your own helpdesk calling. CrowdStrike measured this kind of voice phishing doubling between the second half of 2025 and the first half of 2026.
What happens after the call is the part worth your attention. Once they hold a mailbox, they use it to reset passwords on the applications that sit outside single sign-on, one at a time. Then they delete the confirmation emails, the alerts and the notifications, everything that would have put this in front of a human being. Separately, device-code phishing was reported up 1,500% this year.
Your single sign-on covers what somebody remembered to connect to it. Everything else has its own password reset flow, and that flow trusts an email address.
Somebody in your company knows which applications are on that second list. Ask them for it in writing this week, and notice how long it takes to come back.
THE NOISE
Not every signal needs action.
Millions of Records, Allegedly
Somebody is claiming to have stolen millions of records out of the Azure tenants of several Fortune 500 companies. McDonald's, Tata Consultancy Services and Vodafone have all been named in the coverage. It is a big enough set of logos that this will be in front of you several times this week.
Read that sentence again. Somebody is claiming.
That's a criminal's own account of their own work, handed to reporters, about companies that have confirmed nothing. Claims like this are sometimes true. They are also the cheapest marketing in the criminal economy, and the incentive to inflate runs in exactly one direction. Something will eventually come back from the named companies, and it will be a confirmation, a denial, or a carefully worded paragraph that is neither.
None of those three outcomes changes anything you would do on Monday. You do not have a Fortune 500 data set sitting in your tenant. You have your own, and what matters about it is when anyone last went and looked at who can sign into it and how.
ONE QUESTION
No answer. Just the question.
You have told customers, insurers and an auditor that you have MFA. All three believed you. One of them priced your coverage on it. If a single sign-in path never asked, which of the three do you call first, and what exactly do you tell them?
Where to Start
No link this week. Ten minutes and one email.
Send it to whoever owns identity, in house or outsourced, and ask two things. Which sign-in methods are still enabled on our tenant that we don't use. And what is exempted from our Conditional Access Policy right now, and who approved each exemption.
The first answer is a list. The second one is usually shorter than it should be, and the gap between them is worth your afternoon.
Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal, no scrolling. Find it wherever you listen.
Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io
