Reading various forum and social media posts, this seems to be limited to @me.com and @mac.com addresses. Anyone seen anything else outside of that?
Smells like credential stuffing attack to me at the moment which has triggered some rather vicious account protection measures.