> That's not the same as OneDrive...
I somewhat agree. However, you could have said the same about Facebook, Equifax, Twitter, Yahoo, VK and others. And yet, they all got hacked.
Even Microsoft itself isn't immune: https://www.forbes.com/sites/daveywinder/2020/01/22/microsof...
> How would you know?
If my servers start mining crypto, I've been pwned by script kiddies. If my data becomes available online and is thus available on the previously mentioned site, I've been pwned by more sophisticated attackers. Whereas if we're thinking more along the lines of NSA or Mossad, they are already in my systems and I just have to hope they're in a good mood.
On that note, none of my self hosted mail server related accounts seem to have been leaked so far, or at least haven't been made publically available.
Apart from that, one can also set up alerts for every SSH login, should fail2ban fail for some reason. On app level it becomes harder, to the point where it's often not worth the effort to introduce alerting. Maybe just blanket ban IP ranges that you don't expect to use at ingress level.