The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In July-August 2026, the UNK_CondorFiltration campaign leveraged the TeamFiltration framework to target over 5,700 Microsoft 365 accounts across 28 tenants, primarily focusing on Chilean retail and financial institutions. Operating from 1,487 unique AWS EC2 IP addresses, attackers successfully compromised 7 unmanaged service accounts using default passwords and no multi-factor authentication. The campaign unfolded in three waves, with threat actors gaining access to Microsoft Office, OneDrive, and Teams within minutes of compromise, then pivoting through German VPN nodes to access corporate infrastructure and initiate data exfiltration activities.

This incident highlights the growing trend of attackers targeting forgotten service accounts and leveraging legitimate penetration testing tools for malicious purposes, reflecting broader shifts toward identity-based attacks that exploit basic hygiene gaps rather than sophisticated exploits.

Why This Matters Now

Service accounts with default credentials represent a critical blind spot in enterprise security, especially as organizations accelerate cloud adoption without proper identity governance, making this attack vector increasingly attractive to threat actors.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attackers targeted unmanaged service accounts with default passwords that had never been rotated, allowing compromise of 6 out of 7 accounts within 7 minutes using credential spraying techniques.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained the TeamFiltration attack against Chilean organizations by segmenting cloud access paths and reducing lateral movement scope across Microsoft 365 and Azure resources. The comprehensive segmentation and egress controls could have limited the attackers' ability to pivot through corporate infrastructure and access sensitive data repositories.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security fabric would likely have constrained the attackers' ability to establish persistent foothold across multiple organizational tenants by limiting cross-tenant access paths and reducing the scope of compromised account reach within cloud infrastructure environments.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have reduced the scope of accessible resources by constraining service account privileges to specific workload segments, limiting the attackers' ability to leverage existing permissions across the full range of Office 365 and cloud resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have constrained the attackers' rapid pivoting between VPN infrastructure and corporate cloud resources by enforcing segmented communication paths and reducing reachability from external VPN endpoints to internal Azure and SharePoint environments.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Comprehensive visibility controls would likely have constrained the attackers' sustained access by monitoring and limiting Microsoft Graph API token usage patterns, reducing their ability to maintain persistent command and control channels through compromised cloud accounts across multiple organizational environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have constrained the attackers' data exfiltration capabilities by enforcing controlled outbound access policies for OneDrive and SharePoint resources, reducing the scope and volume of potential data harvesting through compromised Microsoft 365 accounts.

Impact (Mitigations)

Residual organizational impact would likely have been constrained to specific segmented environments rather than enterprise-wide exposure, with reduced blast radius limiting the scope of sensitive data compromise and business disruption across multiple organizational tenants and cloud resource domains.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • Document Collaboration (SharePoint/OneDrive)
  • Customer Financial Services
  • Internal Business Operations
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $150,000

Data Exposure

Potential exposure of corporate documents, email communications, and customer financial data through compromised Microsoft 365 service accounts. Seven unmanaged service accounts were breached across Chilean retail and financial institutions, with threat actors accessing Office applications, OneDrive, Teams, and SharePoint resources for potential data harvesting and exfiltration.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to enforce least privilege access for all service accounts and prevent lateral movement between cloud resources
  • • Deploy Multicloud Visibility & Control to detect anomalous authentication patterns and repeated malformed requests across Microsoft 365 tenants
  • • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration through OneDrive, SharePoint, and Teams applications
  • • Enable Cloud Firewall (ACF) with URL filtering to block credential stuffing attacks from known malicious infrastructure like compromised AWS EC2 instances
  • • Deploy Threat Detection & Anomaly Response capabilities to baseline normal service account behavior and alert on suspicious authentication events and rapid access patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image