Proofpoint researchers have identified a new wave of the TeamFiltration account-takeover campaign, tracked as UNK_CondorFiltration, that targeted more than 5,700 Microsoft 365 accounts across 28 tenants concentrated in Chile between late July and August 2026. The campaign generated over 32,800 authentication attempts from 1,487 unique AWS EC2 source addresses. Seven accounts were compromised, and Proofpoint found that every one of them was an unmanaged functional or service account with no prior legitimate login history, the kind of account that gets provisioned to run a business process and then left unmonitored with its original, never-rotated password and no multi-factor authentication enforced. Six of the seven were breached within seven minutes of each other, consistent with shared default credentials rather than individually cracked passwords.

For identity and access teams, the finding sharpens a blind spot that human-account MFA rollouts do not cover: service and functional accounts sit outside normal joiner-mover-leaver processes and rarely get the same lifecycle scrutiny as employee logins. An attacker running a bulk credential-spraying tool against thousands of tenants only needs a handful of these forgotten accounts to succeed, and post-compromise activity in this campaign included sign-ins from a German VPN node and attempts to reach the corporate VPN, Azure Portal, and SharePoint Online, meaning the initial foothold was not the end goal.

The original insight is in the ratio: 5,714 accounts targeted against seven compromised is a success rate under 0.2 percent, yet the compromised set was compact enough to hand the attacker functioning access to multiple Azure services within minutes. Volume-based spraying defenses that focus on stopping the bulk of failed attempts can still miss the handful of legacy accounts that actually matter, which is why non-human identity inventories remain one of the least watched entry points in most environments, and why credential hygiene for service accounts needs the same rigor now being applied to the identity-based attack paths Microsoft has been disrupting elsewhere.

Source: Proofpoint Threat Insight