In This Article
- What the October 8 Flax Typhoon advisory says
- Three tools aimed at Microsoft 365 mail
- Block the sign-ins a password spray depends on
- Decide which applications may still use EWS
- Find every application that can read mail
- Keep a record of who reads mailboxes
- Your Microsoft 365 email security checklist, and where each control lives
- Questions to prepare for your board and examiners
- How ABT helps financial institutions
- Frequently Asked Questions
Most of the work at a credit union, bank, or mortgage company moves through a mailbox: loan conditions, wire confirmations, member questions, board packets. On October 8, the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA), joined by agencies from six other countries, published a joint advisory. It describes China-linked actors whose techniques are consistent with the activity publicly known as Flax Typhoon. Their tools guess passwords, run scripts, and use stored configuration values to read Microsoft 365 and Exchange mailboxes and copy the mail out.
The advisory ties the activity to Integrity Technology Group, a China-based company it says has links to the Chinese government. The same day, the Justice Department (DOJ) announced court-authorized seizures of two of the company's hacking tools. Three tools in the Flax Typhoon advisory go straight at email: EBurst guesses passwords across Exchange sign-in interfaces, a bot called Curlc4 pulls mail through Exchange Web Services (EWS), and a utility called office-cli keeps reading Microsoft 365 mailboxes using configuration files.
The advisory's named targets are government, critical manufacturing, healthcare, and technology organizations, plus law enforcement, education, and religious groups. The tools aim at Microsoft 365 and Exchange mail in general, and the settings that answer them are ones a credit union, bank, or mortgage company controls today. Four checks answer those three tools: two limit what can sign in or reach mail, one finds what already can, and one records what happened.
Block the older sign-in methods Microsoft calls legacy authentication, which can't do multifactor authentication (MFA), and require MFA for every person who signs in. Review your EWS allow list, which Exchange Online in Microsoft's worldwide commercial cloud requires from October 10 for tenants that have explicitly turned EWS on. Find every application that can read mail, and who added its credentials. Keep the audit records that show which mailboxes were read.
ABT, a Tier-1 Microsoft Cloud Solution Provider serving more than 750 financial institutions, builds Conditional Access and MFA enforcement into Microsoft 365 Guardian. Guardian MxDR watches Microsoft Entra ID for brute force attempts, impossible travel, and legacy authentication attempts, and Guardian Contain detects around the clock and automatically contains what it can.
What the October 8 Flax Typhoon advisory says
Advisory AA26-281A says the actors Integrity Tech enables "use TTPs consistent with the cyber activity publicly known as Flax Typhoon, Ethereal Panda, and Red Juliett, among others." TTPs are tactics, techniques, and procedures.
Microsoft named Flax Typhoon in an August 2023 threat intelligence post about a China-based group whose activity "relies on valid accounts and living-off-the-land binaries," meaning tools already built into the operating system.
The Justice Department's seizures cover MicroScan and FishHub, which DOJ describes as vulnerability scanning and spear phishing tools. One of the five seized FishHub delivery domains, outlook3650[.]com, borrowed Outlook's name.
The advisory says the actors used MicroScan, a web application with more than 1,300 penetration testing scripts, as early as 2017.
Since at least mid-January 2021, the actors have gained access mainly through command-line tools built on exploit code.
The Justice Department disrupts Integrity Tech's botnet of more than 200,000 consumer devices.
Agencies from seven countries publish AA26-281A, and DOJ announces court-authorized seizures that cut off access to MicroScan and FishHub.
Three tools aimed at Microsoft 365 mail
Three of the advisory's tools target email directly, and each one maps to settings in Microsoft 365:
EBurst (password spraying)
An open-source Python tool that, according to the advisory, targets "accounts in the Microsoft Office365 Cloud environment." It sprays and guesses passwords for each email address it's given, across ten Exchange interfaces, including Outlook Web Access, Exchange Web Services, ActiveSync, and Autodiscover.
Curlc4 (EWS mail bot)
A PHP script the FBI says was "specifically designed to interface with the Microsoft EWS API." It pulls email, and the same interface reaches calendars and contacts. Before the mail leaves, the bot compresses it, sometimes encrypting it with a password.
office-cli (mailbox reader)
A command-line tool the actors used "to continuously target and access Microsoft Outlook 365 email accounts," driven by configuration files that hold values such as a client ID, a tenant ID, and a secret.
The advisory adds a line about office-cli that every IT committee should hear:
"The threat actors evade detection when using this program by using legitimate access methods."
The same holds for the other two tools: a password that works produces an ordinary sign-in, and a bot speaking EWS produces ordinary mail traffic. The advisory's mitigations include this instruction: "Monitor cloud accounts for connected applications that can access sensitive data in file systems and email data."
For EBurst, the advisory lists ten interfaces the tool tries and tells defenders to "include these interfaces when defending against EBurst." On a Microsoft 365 tenant, most of that work happens in Conditional Access, the sign-in rules in Microsoft Entra ID.
Block the sign-ins a password spray depends on
Several interfaces on EBurst's list changed in Exchange Online in 2022. Starting October 1, 2022, Microsoft removed Basic authentication, the older sign-in that can't do MFA, in Exchange Online for Exchange ActiveSync, POP, IMAP, Remote PowerShell, Exchange Web Services, the Offline Address Book, and Autodiscover. SMTP AUTH still accepts Basic authentication in tenants where it's turned on, and Microsoft has announced plans to retire it; our guide to the SMTP AUTH deadline covers that change.
Microsoft's guidance goes further: block sign-ins that use legacy protocols, which can't do MFA. That guidance and the 99 percent figure above come from the same Microsoft page. Three settings carry most of the weight:
- Block legacy authentication with Conditional Access. Before you turn the policy on, filter the Microsoft Entra sign-in logs by Client App to see which legacy protocols still sign in, on both the interactive and non-interactive tabs, as Microsoft's instructions describe.
- Require MFA for every person who signs in. Our article on the Conditional Access password spray gap shows where exclusions leave room.
- Treat smart lockout as a speed bump and MFA as the gate. By default, Microsoft Entra smart lockout locks an account after 10 failed attempts, for one minute at first. A spray tries a few passwords across many accounts, so MFA is what decides whether a correct guess gets in.
If your institution still runs an internet-facing Exchange Server, the interfaces on EBurst's list are that server's own interfaces, so start the review there.
Microsoft Entra ID Protection adds two detections that fit this advisory, and both require Microsoft Entra ID P2. The Password spray detection, in Microsoft's words, "is only triggered when an attacker successfully validates a user's password." The Verified threat actor IP detection flags sign-ins from IP addresses "associated with nation state actors or cyber crime groups," based on data from the Microsoft Threat Intelligence Center. Microsoft's 2023 advice on Flax Typhoon applies to both: "Compromised accounts must be closed or changed."
Service accounts often sit outside MFA policies; our review of the forgotten accounts a password spray found covers how to restrict them.
Find out if legacy sign-ins still reach your tenant
ABT's free Guardian Security Assessment reviews MFA coverage, Conditional Access policies, and legacy authentication exposure in your Microsoft 365 tenant.
Decide which applications may still use EWS
Curlc4 was built for Exchange Web Services, the older interface applications use to read and write mail, calendars, and contacts. Microsoft is retiring EWS in Exchange Online, and its published timeline reads: "October 2026: EWS starts to be disabled globally for all organizations," then "April 2027: EWS is fully disabled."
In an October 1 post, Microsoft's Exchange team set the dates for its worldwide commercial cloud, and the first enforcement step lands on October 10. For tenants that had turned EWS on (EWSEnabled set to True) without an allow list as of October 2, Microsoft builds one on October 8 and 9 from the EWS applications used in the previous 60 days. Starting October 10, that allow list, called EWSAllowedAppIDs, is required whenever EWS is turned on. Tenants still on the default setting get a seven-day warning in Message Center before Microsoft turns EWS off for them, with a list built the same way shortly before.
A list built from usage holds whatever used EWS in those 60 days. Microsoft's own guidance on the list says it "may miss applications that run infrequently, and it may include apps you no longer want to have access."
Read the list with Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy in Exchange Online PowerShell and put a name and an owner next to each app ID. Add any approved application that runs too rarely to have made the list, then write back only the applications someone can account for, because setting the list replaces it whole. Microsoft's introduction of EWSAllowedAppIDs notes that changes can take up to 24 hours to take effect.
Find every application that can read mail
The configuration values the advisory names for office-cli (a client ID, a tenant ID, and a secret) are the same three values an application registered in Microsoft Entra ID uses to sign in with its own credentials, with no person at the keyboard. The advisory names the fields and leaves open where the application lived. The defensive question is the same either way: which applications can read mail in your tenant, and who gave them their credentials?
Microsoft's security operations guidance for Entra applications answers the second half. It rates "Added credentials to existing applications" as high risk and points to the Entra audit log activity "Update Application-Certificates and secrets management." Microsoft adds: "Any other credentials added outside expected processes could be a malicious actor using those credentials." It recommends certificates or managed identities over client secrets, with short credential lifetimes.
Then narrow what each approved application can reach. Role Based Access Control (RBAC) for Applications in Exchange Online grants an application mail access limited to a set of mailboxes and replaces Application Access Policies. If the application also keeps an unscoped Mail.Read grant in Microsoft Entra ID, Microsoft says the combination "results in no effective resource scoping," so remove the Entra grant once the scoped role assignment is in place.
App governance in Microsoft Defender for Cloud Apps puts the inventory in one place. Microsoft says it "tells you what permissions the apps have and which users have granted access to their accounts," and it alerts on anomalies in app activity. Our write-ups on Azure service principal security and OAuth consent phishing cover the same applications from the attacker's side.
The three mail tools above call for two kinds of work. Sign-ins are configuration: Conditional Access and MFA decide whether a guessed password matters, and Microsoft 365 Guardian hardens both as part of its baseline and watches them for drift. Applications are lists: the EWS allow list and the credentials on your Entra applications each need an owner, because Microsoft fills the first from past usage when a tenant lacks one, and the second grows every time someone adds a secret.
Keep a record of who reads mailboxes
When a stranger reads a mailbox, a breach review starts with one question: which messages? The MailItemsAccessed audit record is built to help answer it. Microsoft's documentation says it "covers all mail protocols: POP, IMAP, MAPI, EWS, Exchange ActiveSync, and REST," including sync access, where a client downloads a set of messages, and bind access, where someone opens a single message.
MailItemsAccessed is part of Audit (Standard) and is on by default for users with an Office 365 or Microsoft 365 E3 or E5 license. On other plans, confirm in Microsoft Purview that the action is being recorded before you need it.
The advisory's mitigations add the behavior signals: "Monitor for abnormal account activity, such as logons outside of normal working hours and impossible time and distance logons." Guardian MxDR detects impossible travel and risky sign-ins from unknown locations in Microsoft Entra ID logs. Your Microsoft 365 incident response plan should name who acts on those alerts, and how fast.
Your Microsoft 365 email security checklist, and where each control lives
| Control | Where you set it | What it covers |
|---|---|---|
| Block legacy authentication | Conditional Access, Microsoft Entra ID | Password guessing over protocols that can't do MFA, the route EBurst sprays |
| Require MFA for every person | Conditional Access, Microsoft Entra ID | A guessed password on its own |
| Password spray and Verified threat actor IP detections | Microsoft Entra ID Protection (P2) | A spray that found a working password, and sign-ins from known threat actor addresses |
| Review EWSAllowedAppIDs | Exchange Online PowerShell | Applications that can still reach mail over EWS, the interface Curlc4 was built for |
| Alert on new application credentials | Microsoft Entra audit logs | Secrets added outside your normal process |
| Scope application mailbox access | RBAC for Applications, Exchange Online | Applications that can read more mailboxes than they need |
| MailItemsAccessed auditing | Microsoft Purview Audit | Which messages were read, and by which client |
Microsoft 365 Business Premium includes Microsoft Entra ID P1, so the license already covers the two Conditional Access rows. The Entra ID Protection detections need Microsoft Entra ID P2, and app governance runs in Defender for Cloud Apps; Microsoft Defender Suite for Business Premium adds both.
Questions to prepare for your board and examiners
Federal standards set the objectives these settings serve. For mortgage companies and other lenders under the Federal Trade Commission (FTC) Safeguards Rule, MFA is written into the rule itself:
Implement multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls;
Section 314.4(c)(8) adds controls designed to "monitor and log the activity of authorized users." Both apply to every lender the Safeguards Rule covers. Lenders with customer information on fewer than five thousand consumers must meet both as well, because their exemptions in 16 CFR 314.6 cover other sections.
For banks, the Interagency Guidelines Establishing Information Security Standards say each institution "must consider" access controls "to authenticate and permit access only to authorized individuals." The NCUA's guidelines carry parallel language for federally insured credit unions.
Five questions turn those standards into evidence for your board or IT committee:
- Which sign-ins still use legacy authentication, and when did someone last check?
- Does every person's account require MFA, and how are the accounts that can't use it restricted?
- Which applications can read mail in our tenant, who approved each one, and who added its credentials?
- What's on our EWS allow list, and who reviewed it after Microsoft built it?
- Who responds at night to a confirmed password spray or a sign-in from a known threat actor address?
How ABT helps financial institutions
Founded in 1999, ABT serves more than 750 financial institutions as a Tier-1 Microsoft Cloud Solution Provider and manages Microsoft 365 tenants for credit unions, banks, and mortgage companies.
Every level of Microsoft 365 Guardian starts with a hardened tenant. On identity, Guardian covers Conditional Access, MFA enforcement, sign-in risk policies, and guest access controls through Microsoft Entra ID, and it watches for configuration drift, the settings that silently weaken over time. When an account is compromised, Guardian's response phase includes Tokenator automated session revocation and incident containment.
Microsoft said in 2023 that detecting Flax Typhoon's activity "could be challenging" because it relies on valid accounts and built-in tools. Watching for that kind of activity is the job of Guardian MxDR: it detects brute force and credential stuffing attempts through Entra ID Protection and Conditional Access signals, along with impossible travel and legacy authentication attempts. Three Guardian levels sit above the hardened baseline, and each answers an incident differently:
- Guardian Contain: detection around the clock, with automated containment of what it can contain.
- Guardian Respond: an ABT security engineer on covered incidents during business hours.
- Guardian Resolve: a human on the incident at any hour.
ABT's free Guardian Security Assessment reviews MFA coverage, Conditional Access policies, legacy authentication exposure, and admin account hygiene through a read-only connection to your tenant. Most assessments complete within two weeks and end with priority-ranked hardening recommendations and a 90-day roadmap.
Put Guardian MxDR on the sign-ins that matter
Start with a security grade for your Microsoft 365 tenant. Then talk with ABT about Conditional Access, Defender Suite licensing, the applications that can read your mail, and which Guardian level answers a risky sign-in at night.
Frequently Asked Questions
Flax Typhoon is Microsoft's name for a nation-state activity group based in China, described in a Microsoft Threat Intelligence post in August 2023. A joint advisory published October 8, 2026, says the actors enabled by Integrity Technology Group, a China-based company, use techniques consistent with activity publicly known as Flax Typhoon.
No. The advisory names government, critical manufacturing, healthcare, and information technology organizations, along with law enforcement, education, and religious groups. Its email tools aim at Microsoft 365 and Exchange mailboxes in general, so the same Conditional Access, application, and audit controls apply to credit unions, banks, and mortgage companies.
EWSAllowedAppIDs is an Exchange Online setting that lists the applications still allowed to use Exchange Web Services. In Microsoft's worldwide commercial cloud, it is required starting October 10, 2026, for any tenant with EWSEnabled set to True. Review it, because Microsoft built many lists from 60 days of usage, which can miss rarely used apps and keep unwanted ones.
Review the applications in Microsoft Entra ID that hold mail permissions, and watch the Entra audit log for credentials added to existing applications, which Microsoft rates as high risk. App governance in Defender for Cloud Apps shows each app's permissions, and Role Based Access Control (RBAC) for Applications in Exchange Online can limit an app to specific mailboxes.
The Microsoft Entra ID Protection Password spray detection requires Microsoft Entra ID P2, which Microsoft Defender Suite for Business Premium adds, and it fires only after an attacker validates a password. Business Premium includes Microsoft Entra ID P1, with Conditional Access for blocking legacy authentication and requiring multifactor authentication. ABT's Guardian MxDR watches Entra ID for brute force attempts.