# TeamFiltration Exploits Default Passwords to Infiltrate Microsoft 365 Accounts

*Published September 25, 2026*
*Source: [https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html](https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/teamfiltration-exploits-default-passwords-to-infiltrate-microsoft-365-accounts) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A recent cybersecurity investigation by Proofpoint has unveiled a sophisticated TeamFiltration campaign, known as UNK_CondorFiltration, that has targeted more than 5,700 accounts within 28 Microsoft 365 tenants. This campaign has primarily impacted Chilean retail and financial sectors, originating from 1,487 unique AWS EC2 source IP addresses. The attackers compromised seven Microsoft 365 accounts, all of which were unmanaged functional or service accounts rather than individual employee accounts. This highlights a significant vulnerability related to forgotten service accounts that continue to use default or unrotated passwords without multi-factor authentication.

The brute-force campaign unfolded in three distinct waves from late July to August 2026. An unnamed Chilean retailer was the main target, bearing the brunt of 78.3% of the observed authentication events. The attackers used a technique known as password spraying, leveraging default passwords that were initially provisioned by IT teams and never updated. This highlights a critical gap in security practices, as dormant service accounts are often neglected, leaving them unmonitored with their original credentials intact.

TeamFiltration, a legitimate cross-platform offensive framework, was utilized for validating email accounts, testing common or targeted passwords, and potentially harvesting sensitive data from compromised accounts. The framework allowed attackers to gain covert access to Microsoft Office, OneDrive, and Teams. Although the presence of sign-in events alone does not confirm data exfiltration, it raises concerns about potential data breaches. Within minutes of a successful compromise, attackers pivoted to a German VPN node to further explore corporate resources, including the Azure Portal and SharePoint Online.

This is not the first instance of TeamFiltration being used in malicious activities. In June 2025, a similar campaign named UNK_SneakyStrike targeted over 80,000 user accounts using the same open-source penetration testing framework. Proofpoint emphasizes that forgotten service accounts remain a weak link in enterprise security, often overlooked yet critically vulnerable.
