A new cyberattack campaign is exposing an often overlooked security issue in enterprise cloud environments: forgotten service accounts . Proofpoint researchers have identified active TeamFiltration activity , a campaign they are tracking under the codename UNK_CondorFiltration , with attackers targeting more than 5,700 accounts across 28 Microsoft 365 tenants .

The activity was primarily focused on retail and financial organizations in Chile, and 1,487 different IP addresses originating from AWS EC2 infrastructure were used to carry out the attacks . Despite the large number of accounts monitored, researchers confirmed seven breaches .
What's particularly important is that the seven accounts did not belong to employees. They were unmanaged operational and service accounts, several of which were still using original or default passwords and were not protected by MFA.
See also: TeamFiltration attacks target 80,000 Microsoft Entra ID accounts
TeamFiltration – Three waves of attacks on Microsoft 365
The campaign did not manifest as a single attack, but evolved into three different waves between late July and August 2026.
In the first wave, from July 21 to 24 , the attackers targeted approximately 100 to 120 accounts per day and also turned their attention to two major Chilean banking institutions
The second wave took place from July 26 to 28, with activity peaking on July 27, when approximately 1,520 accounts were targeted. This was followed by a sharp decline in activity.
The third and most significant wave occurred from August 13 to 16.On August 15, approximately 1,560 targeted accounts, with a large Chilean retailer accounting for the bulk of the activity. All seven confirmed breaches resulted from this attack.
Password spraying instead of targeted phishing
The findings indicate that the attackers likely used password spraying, which is trying common or default passwords on a large number of accounts, rather than trying to compromise one account at a time.
This option is particularly effective when there are old accounts that have been created for automated tasks and then forgotten by administrators.
In this case, the researchers found that the seven accounts that were compromised were service accounts, which were created for business functions but had not undergone subsequent verification. Six of the seven were compromised in just seven minutes, a finding that reinforces the assessment that a common or default password was used.
TeamFiltration as an attack tool
Central to the campaign was TeamFiltration, a cross-platform framework designed for aggressive testing in Entra ID environments. Among other things, it can be used for account enumeration, password spraying, data collection , and persistent access creation.
See also: BigBear 2.0: New threat bypasses MFA and steals Microsoft 365 accounts
The use of such a tool shows how important it is for organizations to not treat the existence of a penetration-testing framework as an indication of legitimate activity. Tools built for controlled testing can also be exploited by attackers, especially when weak authentication policies are in place.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

From Microsoft 365 to OneDrive, Teams, and SharePoint
Following the breach, the attackers attempted to move within the Microsoft ecosystem. Access to Microsoft Office, OneDrive, and Teams, while activity was also recorded in the Azure Portal and SharePoint Online.
Of particular interest is the fact that less than two minutes after a successful breach, the operator connected via a German VPN node and began exploring corporate services, while at the same time requests related to tokens for the Microsoft Graph API.
Proofpoint clarifies, however, that the presence of links to these services is not in itself proof that data extraction. It is an indication of subsequent activity that requires further investigation.
Forgotten accounts become targets
The UNK_CondorFiltration campaign highlights a problem that often gets overlooked when organizations focus on phishing, exploits, and ransomware attacks.
A service account can be created for a specific task and remain active for years, even after the original need has passed. If it also uses an old password and is not protected by MFA, it can become a particularly attractive entry point.
See also: PREY-0058: Vishing attacks on executives using Microsoft 365
Protection requires regular inventory of all identities, deactivation of unused accounts, unique and strong passwords, implementation of MFA where feasible, and strict restriction of the rights of each service account.

TeamFiltration has been used again
This activity is not an isolated incident. In June 2025, Proofpoint documented the UNK_SneakyStrike, which targeted more than 80,000 accounts in cloud environments of hundreds of organizations, leveraging the same framework.
The message for businesses is clear: Microsoft 365 security is not just about protecting employees. Every digital identity is a potential attack surface, even when it doesn’t belong to a human.
Service accounts created for convenience and then forgotten about can remain active for a long time, offering attackers a less obvious path to critical services and corporate data. This campaign is a reminder that identity management should be an ongoing process, not a check that occurs only when an account is created.
