Breaches · 1 day ago

Proofpoint Finds TeamFiltration on Forgotten Microsoft 365 Accounts

Proofpoint says TeamFiltration’s UNK_CondorFiltration campaign targeted more than 5,700 Microsoft 365 accounts across 28 tenants and compromised seven accounts, all of them unmanaged service or functional accounts. The activity focused on Chilean retail and financial organizations and unfolded in three waves from late July into mid-August.

The campaign appears to have tried default passwords against dormant non-human identities that were never rotated and had no multi-factor authentication. Six of the seven compromises happened within seven minutes, which points to shared or default credentials rather than a slow, user-style login attack; once one of those accounts worked, the actor could reach Microsoft 365 services tied to that tenant.

For organizations that rely on Microsoft 365 and Entra ID, the exposure sits in the identity inventory, not just in employee logins. If service or app accounts were left outside normal password and MFA controls, tenant access can persist even when ordinary user accounts are well defended.

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-25

Editions