Hackers Broke Into Microsoft 365 Through Forgotten Accounts Nobody Was Watching
Proofpoint tracks UNK_CondorFiltration password-spraying campaign compromising seven unmonitored Microsoft 365 service accounts at Chilean organizations via TeamFiltration.
Proofpoint identified a campaign dubbed UNK_CondorFiltration that abused the TeamFiltration framework to spray likely default passwords across 5,714 accounts in 28 Microsoft 365 tenants, mainly targeting Chilean organizations including a large retailer and financial institutions. Seven confirmed compromises all involved functional or service accounts without MFA, clear ownership, or prior legitimate sign-in activity; six were breached within seven minutes. Following successful logins from AWS EC2 infrastructure, attackers accessed Office, OneDrive, Teams, and SharePoint, with one intrusion pivoting through a German VPN node. The August 13-16 wave peaked at about 1,560 targeted accounts on August 15.