Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Accelerate Phishing Investigations: 3 Steps for SOC Teams
September 30, 2026
PaperPhone Headless Browser Network Impersonates 75,000 Mobile Devices Across 43 Countries
September 30, 2026
APT28 Targets Organizations With RedFlick Phishing Attacks
September 30, 2026
Home/Threats/Critical Microsoft 365 Flaw Let Attackers Access Accounts
Threats

Critical Microsoft 365 Flaw Let Attackers Access Accounts

Key Takeaways Attackers successfully breached Microsoft 365 environments by exploiting dormant or unmonitored service accounts. The campaign, identified as UNK_CondorFiltration, leveraged the...

Emy Elsamnoudy
Emy Elsamnoudy
September 30, 2026 4 Min Read
2 0

Key Takeaways

  • Attackers successfully breached Microsoft 365 environments by exploiting dormant or unmonitored service accounts.
  • The campaign, identified as UNK_CondorFiltration, leveraged the TeamFiltration testing framework to conduct widespread password spraying attacks.
  • Seven confirmed compromises occurred across 28 Microsoft 365 tenants, primarily targeting organizations in Chile.
  • The vulnerabilities stemmed from outdated passwords and the absence of multi-factor authentication (MFA) on these service accounts.
  • Post-compromise activities included reconnaissance within Microsoft Office, OneDrive, and Teams, with potential for data exfiltration.

Cybersecurity researchers have uncovered a series of intrusions into Microsoft 365 ecosystems, where threat actors gained unauthorized access by targeting active but neglected accounts. These breaches capitalized on weak security postures, specifically the presence of old passwords and a lack of robust sign-in protections, allowing attackers to infiltrate critical corporate resources such as email, files, and cloud applications.

Table Of Content

  • Key Takeaways
  • Hackers Exploited Forgotten Accounts
  • From Valid Login to Cloud Reconnaissance
  • What You Should Do

The campaign primarily focused on entities within Chile, impacting a major retailer and several financial institutions. Instead of focusing on individual accounts, the attackers utilized a password spraying technique, systematically testing common or default passwords across a large volume of accounts. Successful logins then provided a foothold for further exploration of cloud services.

Analysts at Proofpoint attributed this malicious activity to a campaign they labeled UNK_CondorFiltration. This operation did not involve new malware but rather exploited the legitimate TeamFiltration testing framework. According to a report from Proofpoint, the attackers targeted 5,714 accounts across 28 distinct Microsoft 365 tenants, resulting in seven confirmed compromises.

These statistics highlight a specific and critical vulnerability. None of the confirmed breaches involved standard employee accounts. Instead, every compromised identity was a functional or service account, typically used for automated processes like payment processing, ticketing systems, or point-of-sale operations, and not regularly accessed by human users. These accounts often remain operational without consistent oversight.

Hackers Exploited Forgotten Accounts

Investigations revealed that the seven compromised accounts exhibited no prior legitimate sign-in activity in the available logs. Six of these accounts were breached within a mere seven-minute window, suggesting the attackers exploited either shared or default passwords that had never been changed. Crucially, these accounts were still enabled, lacked clear administrative ownership, and, most critically, appeared to be unprotected by multi-factor authentication (MFA), making a simple valid password sufficient for access.

One particular retailer bore the brunt of the attack, accounting for 25,715 of the campaign’s 32,825 authentication attempts, or 78.3%. The peak of this activity occurred between August 13 and 16, with approximately 1,560 targeted accounts on August 15. All seven confirmed compromises at this retailer transpired on August 14 and 15.

This attack pattern echoes a previous TeamFiltration campaign that also targeted cloud identities. The TeamFiltration framework enables attackers to verify account existence via the Teams API, conduct large-scale password testing, and obscure their origins by cycling through various cloud infrastructure locations. Once access is gained, the framework is capable of collecting data from email, Teams messages, OneDrive, and SharePoint, making unmonitored operational accounts highly attractive targets.

From Valid Login to Cloud Reconnaissance

The attackers’ activities extended beyond merely gaining entry. For most compromised accounts, researchers observed subsequent access to Microsoft Office, OneDrive, and Teams, all originating from the same cloud-hosted infrastructure. This behavior aligns with TeamFiltration’s automated data collection capabilities, although forensic analysis of sign-in logs alone cannot definitively confirm whether files or messages were exfiltrated.

In one documented instance, the attacker swiftly switched to a German VPN node within 90 seconds of the initial compromise. The operator then unsuccessfully attempted to probe the corporate VPN before accessing Azure Portal, OfficeHome, and SharePoint Online. An MFA enrollment prompt encountered during the Azure Portal interaction clearly indicated that the compromised account was not protected by MFA.

Access to SharePoint could facilitate document discovery, data theft, or the planting of malicious files for unsuspecting users. Furthermore, a request for an access token through the SharePoint Online Web Client Extensibility application pointed to attempts to interact with Microsoft Graph or other external application programming interfaces. Such post-login tactics are consistent with reports on hidden cloud mailbox rules, a technique used by intruders to maintain covert visibility into business email communications.

What You Should Do

  • Inventory Service Accounts: Conduct a comprehensive audit of all service and functional accounts. Identify their purpose, associated applications, and assigned permissions.
  • Assign Account Ownership: Ensure every service account has a clear, accountable owner responsible for its lifecycle and security.
  • Deactivate Unused Accounts: Promptly remove or disable any service accounts that are no longer necessary for business operations.
  • Rotate Credentials: Regularly change passwords for service accounts, especially those with inherited or default credentials.
  • Enforce Multi-Factor Authentication (MFA): Implement MFA for all accounts, including service accounts, wherever technically feasible. If MFA isn’t directly supported, explore alternative, safer workload identity solutions.
  • Review Conditional Access Policies: Regularly examine conditional access rules to prevent broad access failures across multiple accounts.
  • Monitor Sign-in Logs: Implement robust logging and alerting for unusual patterns, such as sign-in attempts from distributed cloud hosts, first-time logins, or sudden access to sensitive applications, which can indicate password spraying or other intrusion attempts.
  • Block Legacy Authentication: Where possible, disable legacy or unnecessary authentication protocols that can be exploited for password spraying.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical PaperCut RCE Flaws Let Attackers Compromise Domain Controllers

Next Post

AI Coding Agents Leak 13,000+ Internal Screenshots from 300+ Companies on GitHub

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical PaperCut RCE Flaws Let Attackers Compromise Domain Controllers
September 30, 2026
Attackers Impersonate Zoom, PDF Installers to Deliver Remote Access Trojans
September 30, 2026
Supply Chain Attacks Compromise Developer Machines, Lead to Cloud Breaches
September 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us