Skip to main content
The Wire
CyberNews by Zentrya One
critical Vulnerabilities

TeamFiltration Campaign Compromises Microsoft 365 Service Accounts Using Default Passwords

TeamFiltration attackers targeted over 5,700 Microsoft 365 accounts across 28 tenants, compromising seven unmanaged service accounts using default or unrotated passwords without MFA.

Cybersecurity researchers have uncovered an active Microsoft 365 account-takeover campaign that targeted more than 5,700 accounts across 28 cloud tenants, successfully compromising seven poorly protected service accounts.

Proofpoint tracks the activity as UNK_CondorFiltration. The campaign primarily targeted retail and financial organizations in Chile and relied on TeamFiltration, a legitimate penetration-testing framework that can automate Microsoft Entra ID enumeration, password spraying and post-compromise access.

Campaign at a Glance

Detail Information
Campaign UNK_CondorFiltration
Tool TeamFiltration
Target Microsoft 365 / Entra ID
Accounts Targeted 5,700+
Tenants 28
Compromised Accounts 7
Infrastructure 1,487 AWS EC2 IP addresses
Primary Targets Chilean retail and financial organizations

The attacks occurred in three waves between July 21 and August 16, 2026, generating tens of thousands of authentication attempts.

Forgotten Service Accounts Became the Weak Point

All seven successfully compromised identities were functional or service accounts rather than employee accounts.

Proofpoint found that these accounts had no MFA enforcement and appeared to retain default, predictable, or unrotated passwords. None had prior legitimate user sessions within Proofpoint's observed telemetry.

Six of the seven accounts were compromised within approximately seven minutes, suggesting the attacker may have discovered a common password used when the accounts were originally provisioned.

The attack path was relatively simple:

Account Enumeration → Password Spraying → Forgotten Service Account → Successful Login → Microsoft 365 Access

No zero-day vulnerability or sophisticated exploit was required.

TeamFiltration Automates the Attack

TeamFiltration is an offensive security framework originally designed for testing Microsoft 365 and Entra ID environments.

Its capabilities include:

  • Account enumeration
  • Password spraying
  • Microsoft 365 authentication testing
  • OneDrive access
  • Data collection
  • Persistent cloud access

Proofpoint previously observed another cluster, UNK_SneakyStrike, using TeamFiltration against more than 80,000 accounts across hundreds of organizations.

In the latest campaign, attackers distributed authentication attempts across 1,487 AWS EC2 addresses, making simple IP-based blocking less effective.

What Happened After Compromise?

Following successful authentication, the attackers accessed services including:

  • Microsoft Office
  • OneDrive
  • Microsoft Teams
  • SharePoint Online
  • Azure Portal
  • Microsoft Graph

In one observed case, the attacker switched from AWS infrastructure to a German VPN node within about 90 seconds, attempted to access the victim's corporate VPN, opened Azure Portal and later requested a Microsoft Graph API token.

Proofpoint cautioned that sign-in activity alone does not prove that data was successfully exfiltrated.

What Security Teams Should Do

Organizations using Microsoft 365 should pay particular attention to forgotten non-human identities and service accounts.

Recommended actions include:

  • Inventory all service and functional accounts.
  • Disable accounts that no longer have a valid business purpose.
  • Identify accounts still using default or old passwords.
  • Rotate credentials and avoid shared passwords.
  • Enforce MFA or Conditional Access where technically possible.
  • Replace password-based service accounts with managed or workload identities where supported.
  • Restrict where service accounts can authenticate.
  • Monitor AWS, VPN and geographically unusual authentication activity.
  • Alert on dormant accounts suddenly accessing OneDrive, SharePoint or Microsoft Graph.

Security Takeaway

The TeamFiltration campaign highlights a common identity-security problem: organizations may strongly protect employee accounts while leaving service accounts outside normal identity governance processes.

Forgotten Account + Default Password + No MFA = Cloud Account Takeover

The campaign compromised only seven of thousands of targeted accounts, but every successful compromise involved an unmanaged service or functional identity. That makes stale and poorly governed non-human accounts an important area for Microsoft 365 security teams to review.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.