AI Weekly Malaysia

Back to items Summaries

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

ID
28037
Status
summarized
Published
24 Sep 2026, 2:32 PM
Fetched
24 Sep 2026, 6:14 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.0
Created
24 Sep 2026, 6:15 PM
Tags
Audience
developerssaas_startup_founders

What happened

Proofpoint disclosed an active campaign it calls UNK_CondorFiltration that used the TeamFiltration offensive framework to spray credentials at over 5,700 accounts across 28 Microsoft 365 tenants, originating from 1,487 unique AWS EC2 source IPs. The three waves ran July 21-24, July 26-28, and August 13-16, 2026, against two major Chilean banks and a Chilean retailer, peaking at roughly 1,520 and 1,560 targeted accounts on July 27 and August 15. Seven accounts were compromised - all unmanaged functional or service accounts with default or never-rotated passwords and no MFA, and six of the seven were breached within 7 minutes, which Proofpoint reads as a shared or default password rather than individually targeted credential stuffing.

Why it matters

The one transferable finding is the asymmetry: employee accounts were protected because users are forced to rotate passwords, while the IT-provisioned service accounts that ran business operations were left unmonitored with their original credentials and no MFA. If you run Microsoft 365 or Entra ID, pull the list of non-human identities in your tenant, find which ones still hold the password they were provisioned with, and check whether MFA or conditional access applies to them - that is the exact gap that produced 7 of 7 compromises here. Note this is a Chile-focused campaign, not a Malaysia-specific incident; the relevance is the pattern, not the target list.

Discussion angle

Who owns the service accounts in your tenant? Walk through how many non-human identities your team has provisioned, whether any still carry a default password, and who would notice if one started authenticating from an unfamiliar AWS IP at 3am.

Top