Executive Summary
In July 2026, threat actor UNK_CondorFiltration successfully compromised a major Chilean retailer's Microsoft 365 environment using the open-source TeamFiltration toolkit. After failing to breach employee accounts at multiple Chilean financial institutions, the attacker pivoted to exploit forgotten service accounts with default credentials and no multi-factor authentication. Within seven minutes, six of seven targeted service accounts were compromised, enabling the exfiltration of emails, chat conversations, and files from Outlook, Teams, and OneDrive. The attacker also probed the company's VPN and accessed both M365 and Azure management portals.
This incident highlights the growing threat of identity-based attacks targeting non-human accounts in cloud environments. As organizations strengthen human account security, attackers increasingly focus on overlooked service accounts that lack proper lifecycle management, creating critical security gaps in zero trust implementations.
Why This Matters Now
Organizations are rapidly adopting cloud services and automation, creating proliferating service accounts that often lack proper governance. With human accounts increasingly protected by MFA and security training, threat actors are shifting focus to these forgotten digital identities that represent a critical blind spot in enterprise security postures.
Attack Path Analysis
UNK_CondorFiltration used the TeamFiltration toolkit to conduct credential spraying attacks against Chilean organizations' M365 environments. After failing to compromise employee accounts, the actor discovered seven forgotten service accounts with default credentials and no MFA protection. Using these compromised accounts, the attacker exfiltrated emails, chats, and files from Outlook, Teams, and OneDrive, while also probing VPN infrastructure and accessing Azure management portals.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actor UNK_CondorFiltration used TeamFiltration toolkit to conduct credential spraying attacks against M365 tenants, successfully compromising seven forgotten service accounts with default credentials and no MFA
MITRE ATT&CK® Techniques
Valid Accounts
Brute Force
Valid Accounts: Cloud Accounts
Account Discovery: Email Account
Email Collection: Remote Email Collection
Data from Cloud Storage Object
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography for Authentication Data Storage
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Asset Management and Inventory
Control ID: Identity.AM-1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2.b
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Chilean banks targeted by UNK_CondorFiltration face critical M365 data theft risks through forgotten service accounts bypassing employee security controls and MFA protection.
Retail Industry
Major Chilean retailer compromised via seven unmanaged service accounts enabling TeamFiltration toolkit to exfiltrate emails, files, and access cloud management portals.
Financial Services
Ghost service accounts with default credentials create massive data exfiltration vulnerabilities in M365 environments despite robust employee account security measures implementation.
Information Technology/IT
IT organizations managing M365 tenants face systematic exposure through undocumented service accounts lacking proper lifecycle management, MFA protection, and security oversight.
Sources
- Ghost Service Accounts Enable M365 Data Theft in Chilehttps://www.darkreading.com/cyberattacks-data-breaches/ghost-service-accounts-m365-data-theft-chileVerified
- TeamFiltration - Microsoft 365 Enumeration and Attacking Toolhttps://github.com/Flangvik/TeamFiltrationVerified
- Microsoft 365 Security Best Practiceshttps://docs.microsoft.com/en-us/microsoft-365/security/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce attacker blast radius by enforcing segmented access controls and restricting lateral movement paths. The compromised service accounts' reach would be constrained through workload isolation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust network architecture would likely limit the scope of access available to compromised service accounts through identity-aware segmentation and controlled service exposure.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely constrain the attacker's ability to leverage excessive service account permissions across multiple Microsoft cloud services and reduce cross-service access scope.
Control: East-West Traffic Security
Mitigation: East-west traffic inspection would likely detect and constrain unauthorized movement between M365 services, VPN infrastructure, and Azure management interfaces, reducing attacker reachability across cloud boundaries.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility across cloud environments would likely detect anomalous communication patterns and constrain command and control channels through consistent policy enforcement across multiple cloud services.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely detect and constrain bulk data extraction activities across multiple Microsoft 365 services, reducing the volume and scope of successful data exfiltration.
While some data exposure may still occur, the overall impact would likely be reduced through constrained access scope and limited lateral movement capabilities across segmented cloud environments.
Impact at a Glance
Affected Business Functions
- Customer Payment Processing
- E-commerce Operations
- Inventory Management
- Customer Data Management
Estimated downtime: 2 days
Estimated loss: $250,000
Corporate emails, internal chat conversations, OneDrive files, SharePoint documents, vendor payment information, and potential customer transaction data from a major Chilean retailer
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent service accounts from accessing excessive resources across M365 tenants
- • Deploy Egress Security & Policy Enforcement controls to detect and block unauthorized data exfiltration from Outlook, Teams, OneDrive, and SharePoint
- • Enable Multicloud Visibility & Control capabilities to identify and monitor all service accounts across M365 and Azure environments with centralized policy enforcement
- • Establish Threat Detection & Anomaly Response systems to baseline normal service account behavior and alert on credential spraying attempts like TeamFiltration
- • Implement Cloud Native Security Fabric (CNSF) distributed policy enforcement to provide real-time inspection and autonomous response to prevent similar toolkit-based attacks



