VMTech
Discuss a project →

TeamFiltration hits seven Microsoft 365 service accounts

TeamFiltration hits seven Microsoft 365 service accounts

Proofpoint has detailed an active Microsoft 365 password-spraying campaign, tracked as UNK_CondorFiltration, that targeted more than 5,700 accounts across 28 tenants and compromised seven accounts. All seven were unmanaged functional or service accounts rather than employee accounts, and each retained a default or unrotated password without multi-factor authentication.

The activity primarily affected Chilean retail and financial institutions. Proofpoint observed 1,487 unique AWS EC2 source IP addresses during the campaign, which unfolded in three waves between late July and August 2026.

Service identities were the point of failure

The attackers appear to have sprayed accounts with default passwords, including credentials issued by IT teams and never changed. The focus on dormant service accounts was significant: employee users are typically required to change passwords periodically, while accounts created to run business operations can be left unmonitored with their original credentials still active.

Every confirmed compromise involved an unmonitored service account carrying a default password. Six of the seven accounts were compromised within seven minutes, an observation that Proofpoint said likely points to a shared or default password rather than individual credential-stuffing attempts.

Three waves against Chilean organizations

The first wave ran from July 21 to July 24 and targeted roughly 100 to 120 unique accounts per day at two major Chilean banking institutions. A second wave, from July 26 to July 28, was directed at another major Chilean financial institution and peaked at about 1,520 targeted accounts on July 27 before declining sharply.

The final wave, from August 13 to August 16, targeted a major Chilean retailer. It reached roughly 1,560 accounts on August 15 and resulted in the seven confirmed account compromises. That retailer accounted for 78.3% of all authentication events observed during the campaign.

TeamFiltration expands the available access

The activity used TeamFiltration, a legitimate cross-platform offensive framework built to enumerate, spray, exfiltrate from and backdoor Entra ID accounts. The framework can validate email accounts, test common or targeted passwords against enumerated users, collect sensitive data and provide covert interactive access to OneDrive.

Across most compromised accounts, the operator accessed Microsoft Office, OneDrive and Teams, a pattern potentially consistent with data harvesting and exfiltration. Proofpoint cautioned that sign-in events alone are not proof that data was exfiltrated.

Within less than two minutes of a successful compromise, the operator was observed moving to a German VPN node. From there, the activity included probing a corporate VPN, accessing Azure Portal, browsing SharePoint Online and initiating Microsoft Graph API token requests.

Identity hygiene needs to include non-human accounts

Proofpoint had previously documented TeamFiltration abuse in June 2025, when a cluster called UNK_SneakyStrike targeted more than 80,000 user accounts across hundreds of cloud tenants. The latest activity reinforces that non-human identities can remain exposed even when employee password policies are in place.

For businesses, the practical priority is to maintain an inventory of service and functional accounts, identify dormant identities, rotate inherited or default credentials and apply MFA where the account and service support it. Monitoring those identities for unexpected sign-ins, application access and token requests can help close an attack surface that routine employee controls may miss.

#cybersecurity#identitysecurity#microsoft365#cloudsecurity
Open analytics
On the site 2 views
min read 4 24.09.2026
Instagram

TeamFiltration hits seven Microsoft 365 service accounts

Open the post on Instagram ↗