Hackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts With No MFA
Proofpoint says UNK_CondorFiltration password-sprayed 5,700 Microsoft 365 accounts and breached seven MFA-less service accounts in Chile.
Proofpoint tracked UNK_CondorFiltration password-spraying more than 5,700 Microsoft 365 accounts across 28 tenants between July 21 and August 16, 2026, using the TeamFiltration framework and 1,487 AWS EC2 addresses. The campaign focused on Chilean retail and financial organizations and generated 32,825 authentication events, with one retailer absorbing 78.3% of activity. Seven forgotten service accounts lacking MFA were compromised; none were ordinary employee accounts, and six fell within seven minutes, suggesting a shared provisioning password. Compromised identities accessed Teams, Office, and OneDrive, and one later failed a VPN login after an MFA or Conditional Access block.
- UNK_CondorFiltration sprayed 5,714 Microsoft 365 accounts across 28 tenants.
- Seven forgotten MFA-less service accounts were compromised; employee accounts were not.
- A Chilean retailer absorbed 78.3% of 32,825 events from AWS.
- TeamFiltration enumerated accounts and accessed Teams, Office, and OneDrive.
- Proofpoint urges inventorying service accounts and enforcing phishing-resistant MFA.
Coverage timelineoldest first · each row is one article
- · 1d agoHackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts With No MFA
GBHackers· 74
Proofpoint says UNK_CondorFiltration password-sprayed 5,700 Microsoft 365 accounts and breached seven MFA-less service accounts in Chile.
- · 20h agoHackers Broke Into Microsoft 365 Through Forgotten Accounts Nobody Was Watching
Cyber Security News· 50
Proofpoint tracks UNK_CondorFiltration password-spraying campaign compromising seven unmonitored Microsoft 365 service accounts at Chilean organizations via TeamFiltration.