INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TeamFiltration Compromises Seven Microsoft 365 Accounts with Default Passwords

| 2026-09-24 06:32 LOW HIGH DATA BREACH
Executive Summary
AI-generated
A TeamFiltration campaign, codenamed UNK_CondorFiltration, has compromised seven Microsoft 365 accounts using default passwords in Chile between late July and August 2026. The attackers primarily targeted dormant service accounts provisioned to run business operations but left unmonitored, with six of the seven compromised accounts breached within 7 minutes. The campaign originated from 1,487 unique AWS EC2 source IP addresses and leveraged TeamFiltration, a legitimate cross-platform framework for enumerating, spraying, exfiltrating, and backdooring Entra ID accounts. Affected entities include Chilean retail and financial institutions, with one major retailer facing the brunt of authentication events. The attackers accessed Microsoft Office, OneDrive, Teams, Azure Portal, SharePoint Online, and initiated Microsoft Graph API token requests after gaining foothold in compromised accounts.
Technical Mitigations AI-generated
• Patch default passwords for unmanaged functional or service accounts using Microsoft 365's built-in password rotation feature. • Monitor and rotate default passwords for IT-provisioned credentials, especially those never rotated. • Implement multi-factor authentication (MFA) on all managed identities to prevent unauthorized access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
DACH DACH financefinance retailretail
Incident Timeline
‎August 13-16
Threat actors used default passwords to target approximately 1,560 Microsoft 365 accounts at a major Chilean retailer between August 13 and 16.
target_region Chile
infrastructure Microsoft 365
general_metric 365 Microsoft
general_metric 78.3 %
general_metric 1,520 accounts
general_metric 1,560 accounts
‎July 21-24
Threat actors used default passwords to target approximately 100–120 unique Microsoft 365 accounts per day across three waves from late July to August 2026.
target_region Chile
infrastructure Microsoft 365
general_metric 365 Microsoft
general_metric 78.3 %
general_metric 1,520 accounts
general_metric 1,560 accounts
‎June 2025
Threat actors used the open-source penetration testing framework to target over 80,000 user accounts across hundreds of organizations' cloud tenants in June 2025.
victims 80,000 user
‎July 27
Threat actors used default passwords to target approximately 1,520 Microsoft 365 accounts on July 27.
target_region Chile
infrastructure Microsoft 365
general_metric 365 Microsoft
general_metric 78.3 %
general_metric 1,520 accounts
general_metric 1,560 accounts
‎August 2026
Threat actors compromised seven Microsoft 365 accounts using default passwords, gaining access to various services and potentially harvesting data.
organisation Microsoft Office
organisation Teams
organisation OneDrive
organisation SharePoint Online
organisation Microsoft Graph API
‎August 15
Threat actors sprayed compromised Microsoft 365 accounts with default passwords, including those provisioned by IT teams and never rotated.
target_region Chile
infrastructure Microsoft 365
general_metric 365 Microsoft
general_metric 78.3 %
general_metric 1,520 accounts
general_metric 1,560 accounts
‎Sep 24, 2026
Threat actors used 1,487 unique AWS EC2 source IP addresses to target seven Microsoft 365 accounts using default passwords.
organisation MFA
organisation IP
infrastructure 1,487 source IP addresses
‎late July to August 2026
Threat actors used default passwords to target approximately 100–120 unique Microsoft 365 accounts per day across three waves from late July to August 2026.
target_region Chile
infrastructure Microsoft 365
general_metric 365 Microsoft
general_metric 78.3 %
general_metric 1,520 accounts
general_metric 1,560 accounts
‎2026/09/24
Threat actors using the TeamFiltration campaign codenamed UNK_CondorFiltration compromised seven Microsoft 365 accounts by exploiting default passwords.
infrastructure Microsoft 365
organisation TeamFiltration Campaign Compromises
organisation TeamFiltration
organisation Microsoft
‎July 26-28
Threat actors used default passwords to target approximately 1,520 Microsoft 365 accounts on July 27.
target_region Chile
infrastructure Microsoft 365
general_metric 365 Microsoft
general_metric 78.3 %
general_metric 1,520 accounts
general_metric 1,560 accounts
Tactical Metrics
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
infrastructure
1,487
Source Ip Addresses
Metrics
victims
80,000
User
Intelligence Sources