The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In July 2026, threat actor UNK_CondorFiltration successfully compromised a major Chilean retailer's Microsoft 365 environment using the open-source TeamFiltration toolkit. After failing to breach employee accounts at multiple Chilean financial institutions, the attacker pivoted to exploit forgotten service accounts with default credentials and no multi-factor authentication. Within seven minutes, six of seven targeted service accounts were compromised, enabling the exfiltration of emails, chat conversations, and files from Outlook, Teams, and OneDrive. The attacker also probed the company's VPN and accessed both M365 and Azure management portals.

This incident highlights the growing threat of identity-based attacks targeting non-human accounts in cloud environments. As organizations strengthen human account security, attackers increasingly focus on overlooked service accounts that lack proper lifecycle management, creating critical security gaps in zero trust implementations.

Why This Matters Now

Organizations are rapidly adopting cloud services and automation, creating proliferating service accounts that often lack proper governance. With human accounts increasingly protected by MFA and security training, threat actors are shifting focus to these forgotten digital identities that represent a critical blind spot in enterprise security postures.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Organizations should implement service account lifecycle management, assign ownership to human employees, set expiration dates, and regularly audit accounts that don't follow standard naming conventions.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce attacker blast radius by enforcing segmented access controls and restricting lateral movement paths. The compromised service accounts' reach would be constrained through workload isolation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero trust network architecture would likely limit the scope of access available to compromised service accounts through identity-aware segmentation and controlled service exposure.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely constrain the attacker's ability to leverage excessive service account permissions across multiple Microsoft cloud services and reduce cross-service access scope.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic inspection would likely detect and constrain unauthorized movement between M365 services, VPN infrastructure, and Azure management interfaces, reducing attacker reachability across cloud boundaries.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility across cloud environments would likely detect anomalous communication patterns and constrain command and control channels through consistent policy enforcement across multiple cloud services.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely detect and constrain bulk data extraction activities across multiple Microsoft 365 services, reducing the volume and scope of successful data exfiltration.

Impact (Mitigations)

While some data exposure may still occur, the overall impact would likely be reduced through constrained access scope and limited lateral movement capabilities across segmented cloud environments.

Impact at a Glance

Affected Business Functions

  • Customer Payment Processing
  • E-commerce Operations
  • Inventory Management
  • Customer Data Management
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $250,000

Data Exposure

Corporate emails, internal chat conversations, OneDrive files, SharePoint documents, vendor payment information, and potential customer transaction data from a major Chilean retailer

Recommended Actions

  • • Implement Zero Trust Segmentation to enforce least privilege access and prevent service accounts from accessing excessive resources across M365 tenants
  • • Deploy Egress Security & Policy Enforcement controls to detect and block unauthorized data exfiltration from Outlook, Teams, OneDrive, and SharePoint
  • • Enable Multicloud Visibility & Control capabilities to identify and monitor all service accounts across M365 and Azure environments with centralized policy enforcement
  • • Establish Threat Detection & Anomaly Response systems to baseline normal service account behavior and alert on credential spraying attempts like TeamFiltration
  • • Implement Cloud Native Security Fabric (CNSF) distributed policy enforcement to provide real-time inspection and autonomous response to prevent similar toolkit-based attacks

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image