Forgotten Service Accounts Exploited in Microsoft 365 Password-Spraying Campaign
Researchers at Proofpoint have detailed an active campaign, tracked as UNK_CondorFiltration, that targeted over 5,700 Microsoft 365 accounts across 28 tenants using a tool called TeamFiltration. The activity, observed in three waves between late July and August 2026, primarily hit Chilean retail and financial organisations and was launched from nearly 1,500 unique AWS EC2 IP addresses.
While the scale sounds alarming, only seven accounts were actually compromised, and all were unmanaged service or functional accounts rather than individual employee logins. These accounts had been set up by IT teams to run business operations but were then left unmonitored, still carrying their original default passwords and no multi-factor authentication. Six of the seven were broken into within just seven minutes, suggesting attackers were using known default credentials rather than guessing individually.
Once inside, the attacker used TeamFiltration, a legitimate but repurposed offensive security framework, to access Office, OneDrive and Teams, raising concerns about potential data harvesting. Proofpoint notes that sign-in activity alone does not confirm data was stolen, but the access itself represents a serious exposure.