Executive Summary
In July-August 2026, the UNK_CondorFiltration campaign leveraged the TeamFiltration framework to target over 5,700 Microsoft 365 accounts across 28 tenants, primarily focusing on Chilean retail and financial institutions. Operating from 1,487 unique AWS EC2 IP addresses, attackers successfully compromised 7 unmanaged service accounts using default passwords and no multi-factor authentication. The campaign unfolded in three waves, with threat actors gaining access to Microsoft Office, OneDrive, and Teams within minutes of compromise, then pivoting through German VPN nodes to access corporate infrastructure and initiate data exfiltration activities.
This incident highlights the growing trend of attackers targeting forgotten service accounts and leveraging legitimate penetration testing tools for malicious purposes, reflecting broader shifts toward identity-based attacks that exploit basic hygiene gaps rather than sophisticated exploits.
Why This Matters Now
Service accounts with default credentials represent a critical blind spot in enterprise security, especially as organizations accelerate cloud adoption without proper identity governance, making this attack vector increasingly attractive to threat actors.
Attack Path Analysis
Threat actors used TeamFiltration framework to conduct credential stuffing attacks against unmanaged Microsoft 365 service accounts with default passwords across Chilean organizations. After compromising 7 accounts within minutes, attackers pivoted through German VPN infrastructure to access corporate resources including Azure Portal, SharePoint, and OneDrive for potential data harvesting and exfiltration.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers leveraged TeamFiltration framework from 1,487 AWS EC2 IP addresses to spray default passwords against 5,700 Microsoft 365 accounts across 28 tenants, successfully compromising 7 unmanaged service accounts lacking MFA
MITRE ATT&CK® Techniques
Brute Force: Password Spraying
Valid Accounts: Cloud Accounts
Brute Force: Credential Stuffing
Account Discovery: Email Account
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Remote Services: Cloud Services
Credentials from Password Stores: Cloud Secrets Management Stores
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
PCI DSS 4.0 – Strong Cryptography for Authentication Credentials
Control ID: 8.2.1
CISA Zero Trust Maturity Model 2.0 – Identity Inventory and Management
Control ID: ID.AM-2
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21(2)(a)
NIST SP 800-53 – Password-Based Authentication
Control ID: IA-5(1)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Chilean banking institutions directly targeted by TeamFiltration credential stuffing attacks compromising service accounts with default passwords, requiring enhanced Zero Trust segmentation.
Retail Industry
Major Chilean retailer suffered 78.3% of authentication attacks and seven account compromises, exposing critical gaps in unmanaged service account security controls.
Information Technology/IT
Microsoft 365 tenant compromises across 28 organizations highlight urgent need for egress security policies and threat detection capabilities for cloud environments.
Computer/Network Security
TeamFiltration framework exploitation demonstrates requirements for multicloud visibility, encrypted traffic monitoring, and anomaly detection to prevent credential-based attacks.
Sources
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwordshttps://thehackernews.com/2026/09/teamfiltration-compromises-seven.htmlVerified
- Proofpoint Threat Insight: UNK_CondorFiltration Campaign Analysishttps://www.proofpoint.com/us/blog/threat-insight/teamfiltration-campaign-targets-microsoft-365-accountsVerified
- Microsoft 365 Security Best Practices - Service Account Managementhttps://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/recommended-settings-for-eop-and-office365Verified
- CISA Alert: Securing Cloud Services Against Password Attackshttps://www.cisa.gov/news-events/cybersecurity-advisories/aa23-277aVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained the TeamFiltration attack against Chilean organizations by segmenting cloud access paths and reducing lateral movement scope across Microsoft 365 and Azure resources. The comprehensive segmentation and egress controls could have limited the attackers' ability to pivot through corporate infrastructure and access sensitive data repositories.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric would likely have constrained the attackers' ability to establish persistent foothold across multiple organizational tenants by limiting cross-tenant access paths and reducing the scope of compromised account reach within cloud infrastructure environments.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have reduced the scope of accessible resources by constraining service account privileges to specific workload segments, limiting the attackers' ability to leverage existing permissions across the full range of Office 365 and cloud resources.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained the attackers' rapid pivoting between VPN infrastructure and corporate cloud resources by enforcing segmented communication paths and reducing reachability from external VPN endpoints to internal Azure and SharePoint environments.
Control: Multicloud Visibility & Control
Mitigation: Comprehensive visibility controls would likely have constrained the attackers' sustained access by monitoring and limiting Microsoft Graph API token usage patterns, reducing their ability to maintain persistent command and control channels through compromised cloud accounts across multiple organizational environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have constrained the attackers' data exfiltration capabilities by enforcing controlled outbound access policies for OneDrive and SharePoint resources, reducing the scope and volume of potential data harvesting through compromised Microsoft 365 accounts.
Residual organizational impact would likely have been constrained to specific segmented environments rather than enterprise-wide exposure, with reduced blast radius limiting the scope of sensitive data compromise and business disruption across multiple organizational tenants and cloud resource domains.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Collaboration (SharePoint/OneDrive)
- Customer Financial Services
- Internal Business Operations
Estimated downtime: 2 days
Estimated loss: $150,000
Potential exposure of corporate documents, email communications, and customer financial data through compromised Microsoft 365 service accounts. Seven unmanaged service accounts were breached across Chilean retail and financial institutions, with threat actors accessing Office applications, OneDrive, Teams, and SharePoint resources for potential data harvesting and exfiltration.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to enforce least privilege access for all service accounts and prevent lateral movement between cloud resources
- • Deploy Multicloud Visibility & Control to detect anomalous authentication patterns and repeated malformed requests across Microsoft 365 tenants
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration through OneDrive, SharePoint, and Teams applications
- • Enable Cloud Firewall (ACF) with URL filtering to block credential stuffing attacks from known malicious infrastructure like compromised AWS EC2 instances
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal service account behavior and alert on suspicious authentication events and rapid access patterns



