Forgotten service accounts cracked open 28 Microsoft 365 tenants

Proofpoint linked 28 Microsoft 365 tenant intrusions to unrotated service accounts still holding default passwords.

CSBadmin
2 Min Read

Every account the intruders broke into was a service account still running on a default password, and the campaign behind it touched more than 5,700 accounts spread across 28 Microsoft 365 tenants. Proofpoint, which labels the cluster UNK_CondorFiltration, counted seven compromises in all.

The batch ran in three waves from late July to August 2026 and leaned on Chilean retail and financial firms, with traffic arriving from 1,487 unique AWS EC2 addresses.

Daily spraying peaked around 1,520 accounts in late July and about 1,560 in mid-August. A single Chilean retailer absorbed 78.3 percent of all observed authentication events.

Six of the seven accounts were taken inside seven minutes. That pace fits a shared or default password better than credential stuffing aimed at particular people.

The tooling was TeamFiltration, a legitimate open-source offensive framework that can enumerate Entra ID accounts, spray passwords at them, pull data out, and leave a backdoor behind, including covert interactive access to OneDrive.

Less than two minutes after a sign-in went through, the operator was already out through a German VPN node. From there the operator probed the corporate VPN, requested Microsoft Graph tokens, browsed SharePoint Online and opened the Azure Portal.

Most victims saw Office, OneDrive and Teams pulled into reach, which Proofpoint treats as data harvesting rather than proof of theft. Sign-in logs on their own, it notes, do not show that anything left.

Proofpoint’s warning is that a dormant identity keeps standing up the business after everyone stops watching it. Employees are made to rotate passwords on a schedule; service accounts usually are not, and many never get a second factor.

TeamFiltration has form: a cluster Proofpoint called UNK_SneakyStrike used it in June 2025 against more than 80,000 accounts held in hundreds of tenants.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.