A Distributed Credential Campaign Hit 1,520 Times from 1,510 Unique IPs Across 44 Countries and Never Once Got In
A Plano-based EHR software vendor had no visibility into their Microsoft 365 tenant. No SaaS-layer monitoring, no geographic baseline, no awareness of anonymous external sharing. We built the detection model, and over nine months it surfaced a sustained distributed credential campaign engineered to evade per-IP lockouts, contained a data access event from Seoul in under 15 minutes, and held zero PHI exposure throughout.
The Challenge
This company builds and maintains EHR software used by hospitals and clinics. Every healthcare organization running their platform depends on them to protect the integrity of that software supply chain. If their Microsoft 365 tenant is compromised, the downstream exposure does not stop at their own data. It extends to every clinical operation that relies on them.
When we onboarded them, there was no SaaS-layer monitoring in place. No one was watching authentication events, no geographic baseline had been established, and no one had visibility into anonymous external share links. The native Microsoft 365 tooling was the only lens available, and that tooling does not aggregate distributed patterns across identities or time.
The added complexity was geography. This company legitimately operates in the United States and Colombia. Personnel in Plano, Richardson, Bogotá, and Medellín all needed normal, uninterrupted access. A binary "foreign login equals block" policy would have broken operations immediately. The detection model had to be granular enough to distinguish legitimate two-country activity from actual threat behavior.
No SaaS Visibility
Zero monitoring of Microsoft 365 authentication, sharing, or access events. There was no mechanism to detect a distributed credential campaign, geographic anomaly, or data access event.
Two-Country Operations
US and Colombia locations meant geographic anomaly detection could not be binary. A model that blocked all non-US access would have shut down legitimate personnel in Bogotá and Medellín.
EHR Supply Chain Position
As an upstream EHR vendor, a tenant compromise carries consequences beyond their own data. Every hospital and clinic running their software sits downstream of a security failure here.
What the Monitoring Found
Across 43,865 events monitored over approximately nine months, three findings defined the engagement. The most operationally significant was a distributed credential campaign that never appeared as a single threat in native Microsoft 365 tooling because it was specifically engineered not to.
The Distributed Credential Campaign
A single identity absorbed 1,520 failed authentication attempts originating from 1,510 unique IP addresses across 44 countries. Of those 1,510 source IPs, 1,500 were used exactly once. This is not a brute force attack. Brute force repeats from a source. This was a distributed credential campaign built to stay under every per-IP lockout threshold that Microsoft enforces. Each IP contributes one attempt and disappears.
To native Microsoft 365 tooling, this looks like 1,520 unrelated failed password entries spread across time and geography. There is no native view that assembles 1,510 separate source addresses into a single adversary. Aggregation across the full event dataset is what surfaces the pattern.
Month-by-Month Escalation
The campaign did not arrive at full intensity. It ramped systematically over eight months, then expanded its source diversity. This escalation profile is only visible when the full nine-month event set is laid out sequentially.
| Month | Attempts | Countries | Notable |
|---|---|---|---|
| Month 1 | 2 | 2 | Campaign begins |
| Month 2 | 7 | 5 | Probe phase |
| Month 3 | 31 | 8 | Volume climbing |
| Month 4 | 89 | 11 | Accelerating |
| Month 5 | 194 | 14 | Consistent ramp |
| Month 6 | 298 | 18 | Heavy pressure |
| Month 7 | 174 | 17 | Sustained |
| Month 8 | 725 | 24 | 350x Month 1 |
Month 8 produced 725 attempts, 350 times the volume of Month 1. Source country diversity nearly doubled to over 20 countries in that same period. The pattern is consistent with a credential campaign that had validated the target, confirmed no lockout response, and escalated pressure accordingly.
Campaign outcome: zero successful compromise. Every confirmed successful login traced to approved geography. Plano, Richardson, Bogotá, Medellín. Zero successful logins from any hostile address. MFA was enforced across all accounts throughout the engagement.
Data That Actually Moved
The same identity targeted by the credential campaign had created anonymous SharePoint share links. Those links were redeemed from Seoul, South Korea. Six access events occurred within a 29-second window, resulting in two documents downloaded.
The analyst response followed a deliberate protocol: lock first, investigate second. The account was precautionarily locked before any determination was made about whether the access was malicious. This sequence matters. Waiting for attribution before acting gives a threat actor time to move. The account was locked in under 15 minutes from the initial alert.
Seoul Access Event
Post-investigation confirmed both documents were sales and marketing collateral. No client data and no PHI were contained in either file. The "lock first, investigate second" protocol meant the outcome was determined by response speed, not by what the files happened to contain.
The Geographic Detection Model
Both detections above required a geographic model that could distinguish legitimate two-country operations from actual threat activity. We built a tiered policy that made this possible without blocking the Colombia team or drowning analysts in alerts from low-risk countries.
Tier 1: Approved
No AlertUnited States and Colombia. Access from approved geography generates no alert and requires no analyst time. Legitimate personnel in Plano, Richardson, Bogotá, and Medellín continue without interruption.
Tier 2: Flag and Hold
Analyst TriageAll other countries not on the auto-lockdown list. Access events are flagged, queued for analyst review, and held until disposition. The Seoul event entered this tier, which is why the 15-minute containment was possible.
Tier 3: Auto-Lockdown
No Human Needed30 OFAC-sanctioned countries. Any access attempt from these jurisdictions triggers automatic lockdown with no analyst decision required. Immediate response without analyst latency for the highest-risk geographies.
Over nine months, 52 countries touched the tenant. The three-tier model meant 272 out-of-geography access events were handled without any impact to US or Colombia operations.
Results
All numbers come from client event data collected over approximately nine months of continuous monitoring.
Total Microsoft 365 events analyzed across approximately nine months. 39 of 58 identities were actively generating events during the monitoring period.
1,500 of 1,510 hostile IPs used exactly once. The distributed credential campaign was assembled from 44 countries and never succeeded at authentication.
Time from Seoul access event alert to precautionary account lockdown. "Lock first, investigate second" protocol applied without waiting for attribution.
Out of 1,959 in-app alerts and 1,249 email escalations, 72 were classified critical severity. The escalation model kept analyst focus on the events that warranted it.
Countries that touched the tenant over nine months
Access events outside approved geography, all handled by tiered model
External share links tracked throughout the engagement
The Graduated Model Was the Control That Made Both Detections Possible
A binary geographic policy, block all foreign access or block none, would have failed this client in one of two ways. Blocking all foreign access would have shut down legitimate Colombia operations on day one. Blocking nothing would have left the credential campaign and the Seoul access event invisible at the geographic layer, relying solely on Microsoft's native tooling to surface patterns it cannot aggregate.
The graduated three-tier model meant analysts were not looking at all 272 out-of-geography events equally. The 30 OFAC countries resolved automatically. The Seoul event went into the analyst queue as a flagged item and received a response decision in under 15 minutes. The credential campaign was surfaced because aggregating authentication failures across 1,510 separate source IPs was being done at the monitoring layer, not left to a tool with no cross-IP view.
The insight that applies beyond this engagement: SaaS-layer threats are not visible to infrastructure controls. A next-generation firewall, an endpoint agent, and a network sensor cannot see a distributed credential campaign inside Microsoft 365. The detection layer has to match where the threat is operating. Learn more about how we structure managed SOC coverage for SaaS environments and our approach to healthcare compliance monitoring.
No View Into Your Microsoft 365 Tenant
If your SaaS layer has no monitoring, you have no way to know whether a distributed credential campaign is already underway against your identities. Native M365 tooling does not aggregate across 1,500 source IPs. We do.
Serving Plano, McKinney, and the DFW metro. Email security and compliance monitoring also available.