@GossiTheDog One note.. the article mentions a small number of accounts but then it says this: "Midnight Blizzard’s use of residential proxies to obfuscate connections makes traditional indicators of compromise (IOC)-based detection infeasible due to the high changeover rate of IP addresses." So they saw failed logins from a large number of IP addresses for a small number of users and they didnt think to investigate that?