TeamFiltration Campaign Exploits Default Passwords to Compromise Microsoft 365 Accounts
A sophisticated TeamFiltration campaign has targeted over 5,700 Microsoft 365 accounts, successfully compromising seven by exploiting forgotten service accounts with default passwords.

A persistent cyber campaign, identified as TeamFiltration and codenamed UNK_CondorFiltration, has been actively targeting Microsoft 365 accounts, with researchers from Proofpoint uncovering activity impacting over 5,700 accounts across 28 different tenants. The campaign has predominantly focused on organizations within Chile's retail and financial sectors, leveraging a vast infrastructure of 1,487 unique AWS EC2 IP addresses to conduct its operations.
The primary success of this campaign lies in its exploitation of a critical security gap: unmanaged, non-human identities. Specifically, seven Microsoft 365 accounts were compromised, all of which were functional or service accounts rather than individual employee accounts. This highlights a significant exposure risk associated with dormant accounts that retain default passwords and lack multi-factor authentication (MFA), often overlooked in standard security practices.
The malicious activity unfolded across three distinct waves between late July and mid-August 2026. The initial wave, from July 21-24, targeted approximately 100-120 accounts daily against two major Chilean banking institutions. A subsequent surge occurred from July 26-28, peaking at around 1,520 accounts on July 27, directed at another significant Chilean financial entity. The most impactful wave occurred from August 13-16, targeting a major Chilean retailer and leading to the seven successful account compromises.
Analysis suggests the threat actor employed a brute-force approach, spraying accounts with common or default passwords, including credentials that were provisioned by IT teams and never subsequently rotated. The campaign's focus on dormant service accounts, which are often left unmonitored and retain their original credentials, proved particularly effective. Unlike individual employee accounts, these service accounts are not subject to regular password changes, making them persistent targets.
Evidence indicates a rapid compromise of six of the seven accounts, often occurring within seven minutes of initial access. This suggests the use of shared or default passwords rather than individually targeted credential stuffing. The threat actor utilized TeamFiltration, a legitimate offensive framework designed for account enumeration, spraying, data exfiltration, and backdoor access within Entra ID environments, to automate and scale their attacks.
Following successful compromise, the threat actor typically accessed Microsoft Office, OneDrive, and Teams, indicating potential data harvesting and exfiltration activities, although sign-in events alone do not confirm exfiltration. Within minutes of gaining access, operators were observed pivoting to German VPN nodes to probe corporate VPNs, access the Azure Portal, browse SharePoint Online, and initiate Microsoft Graph API token requests, demonstrating a clear intent to explore and exploit the compromised environment.
This is not the first instance of TeamFiltration being used maliciously; Proofpoint previously detailed another threat cluster, UNK_SneakyStrike, which utilized the same framework to target over 80,000 user accounts across numerous organizations in June 2025. The UNK_CondorFiltration campaign serves as a stark reminder that often the most vulnerable points in an enterprise's identity perimeter are not sophisticated exploits but rather forgotten service accounts with default credentials, representing a structurally unprotected attack surface.
This campaign underscores the critical need for organizations to regularly audit and manage all service accounts, ensuring they are not only secured with strong, unique passwords but also protected by multi-factor authentication and subject to regular monitoring and rotation policies. The compromise of these often-overlooked accounts can provide attackers with a significant foothold into an organization's cloud infrastructure.