Breaches · 1 day ago
Proofpoint says TeamFiltration’s UNK_CondorFiltration campaign targeted more than 5,700 Microsoft 365 accounts across 28 tenants and compromised seven accounts, all of them unmanaged service or functional accounts. The activity focused on Chilean retail and financial organizations and unfolded in three waves from late July into mid-August.
The campaign appears to have tried default passwords against dormant non-human identities that were never rotated and had no multi-factor authentication. Six of the seven compromises happened within seven minutes, which points to shared or default credentials rather than a slow, user-style login attack; once one of those accounts worked, the actor could reach Microsoft 365 services tied to that tenant.
For organizations that rely on Microsoft 365 and Entra ID, the exposure sits in the identity inventory, not just in employee logins. If service or app accounts were left outside normal password and MFA controls, tenant access can persist even when ordinary user accounts are well defended.
1 source covering this story
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
TeamFiltration targeted over 5,700 Microsoft 365 accounts across 28 tenants, compromising seven service accounts with default passwords.
Part of the PlainSec briefing for 2026-09-25