TeamFiltration Campaign Compromises Microsoft 365 Service Accounts Using Default Passwords
TeamFiltration attackers targeted over 5,700 Microsoft 365 accounts across 28 tenants, compromising seven unmanaged service accounts using default or unrotated passwords without MFA.

Cybersecurity researchers have uncovered an active Microsoft 365 account-takeover campaign that targeted more than 5,700 accounts across 28 cloud tenants, successfully compromising seven poorly protected service accounts.
Proofpoint tracks the activity as UNK_CondorFiltration. The campaign primarily targeted retail and financial organizations in Chile and relied on TeamFiltration, a legitimate penetration-testing framework that can automate Microsoft Entra ID enumeration, password spraying and post-compromise access.
Campaign at a Glance
| Detail | Information |
|---|---|
| Campaign | UNK_CondorFiltration |
| Tool | TeamFiltration |
| Target | Microsoft 365 / Entra ID |
| Accounts Targeted | 5,700+ |
| Tenants | 28 |
| Compromised Accounts | 7 |
| Infrastructure | 1,487 AWS EC2 IP addresses |
| Primary Targets | Chilean retail and financial organizations |
The attacks occurred in three waves between July 21 and August 16, 2026, generating tens of thousands of authentication attempts.
Forgotten Service Accounts Became the Weak Point
All seven successfully compromised identities were functional or service accounts rather than employee accounts.
Proofpoint found that these accounts had no MFA enforcement and appeared to retain default, predictable, or unrotated passwords. None had prior legitimate user sessions within Proofpoint's observed telemetry.
Six of the seven accounts were compromised within approximately seven minutes, suggesting the attacker may have discovered a common password used when the accounts were originally provisioned.
The attack path was relatively simple:
Account Enumeration → Password Spraying → Forgotten Service Account → Successful Login → Microsoft 365 Access
No zero-day vulnerability or sophisticated exploit was required.
TeamFiltration Automates the Attack
TeamFiltration is an offensive security framework originally designed for testing Microsoft 365 and Entra ID environments.
Its capabilities include:
- Account enumeration
- Password spraying
- Microsoft 365 authentication testing
- OneDrive access
- Data collection
- Persistent cloud access
Proofpoint previously observed another cluster, UNK_SneakyStrike, using TeamFiltration against more than 80,000 accounts across hundreds of organizations.
In the latest campaign, attackers distributed authentication attempts across 1,487 AWS EC2 addresses, making simple IP-based blocking less effective.
What Happened After Compromise?
Following successful authentication, the attackers accessed services including:
- Microsoft Office
- OneDrive
- Microsoft Teams
- SharePoint Online
- Azure Portal
- Microsoft Graph
In one observed case, the attacker switched from AWS infrastructure to a German VPN node within about 90 seconds, attempted to access the victim's corporate VPN, opened Azure Portal and later requested a Microsoft Graph API token.
Proofpoint cautioned that sign-in activity alone does not prove that data was successfully exfiltrated.
What Security Teams Should Do
Organizations using Microsoft 365 should pay particular attention to forgotten non-human identities and service accounts.
Recommended actions include:
- Inventory all service and functional accounts.
- Disable accounts that no longer have a valid business purpose.
- Identify accounts still using default or old passwords.
- Rotate credentials and avoid shared passwords.
- Enforce MFA or Conditional Access where technically possible.
- Replace password-based service accounts with managed or workload identities where supported.
- Restrict where service accounts can authenticate.
- Monitor AWS, VPN and geographically unusual authentication activity.
- Alert on dormant accounts suddenly accessing OneDrive, SharePoint or Microsoft Graph.
Security Takeaway
The TeamFiltration campaign highlights a common identity-security problem: organizations may strongly protect employee accounts while leaving service accounts outside normal identity governance processes.
Forgotten Account + Default Password + No MFA = Cloud Account Takeover
The campaign compromised only seven of thousands of targeted accounts, but every successful compromise involved an unmanaged service or functional identity. That makes stale and poorly governed non-human accounts an important area for Microsoft 365 security teams to review.
Related reporting
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock ransomware attackers exploit Microsoft SharePoint vulnerabilities to gain initial access, disable security tools and distribute ransomware across critical infrastructure networks.
Apple CoreGraphics Zero-Day PoC Emerges as WhatsApp PDF Checks Raise Delivery Questions
A public PoC for Apple CoreGraphics CVE-2026-86950 demonstrates memory corruption through a malicious PDF, while new WhatsApp PDF protections raise questions about a possible delivery path.
Kiteworks Fixes Critical Vulnerability Discovered During Emergency Shutdown
Kiteworks patched a previously unknown critical vulnerability discovered during a nine-hour precautionary shutdown prompted by intelligence about a potential cyberattack, with no evidence of exploitation.


