Skip to content

Security1 publisher2 min readPublished

Password spraying across more than 5,700 Chilean M365 accounts broke into only seven unused service accounts

Proofpoint says an unknown actor sprayed over 5,700 M365 accounts in Chile and breached only seven, all dormant service accounts at one retailer. Employee logins held, and those seven unused accounts still gave the attacker mail, Teams chats, OneDrive files and, in one case, the Azure portal.

The Watch · Security desk

Illustration accompanying Password spraying across more than 5,700 Chilean M365 accounts broke into only seven unused service accounts

What happened

  • Proofpoint disclosed a previously unknown actor, tracked as UNK_CondorFiltration, attacking Chilean organizations' M365 tenants at its Protect 2026 conference in San Diego.
  • From July 21 the actor probed hundreds of accounts at two major Chilean banks, then thousands at a third financial institution a week later, with little apparent result.
  • After two quiet weeks, a mid-August wave aimed at a single major Chilean retailer compromised seven corporate accounts.
  • Across more than 5,700 accounts in 28 tenants, the actor never breached an account belonging to an employee.
  • In at least one case the attacker went past mail and file theft to probe the VPN, open the M365 management and Azure portals, and browse SharePoint.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A tenant that hardens staff logins but leaves unused functional accounts with passwords can still be entered with a free, five-year-old toolkit and no exploit.
  • decision Identity teams have to treat functional and service accounts as a population they own, including ones created without documentation, and disable those whose purpose has ended.
  • capability Accounts with no sign-in history give defenders an alert that needs no tuning: the first sign-in to one is the event worth investigating.

No CVE is involved and there is no patch deadline. Exploitability is high, and little skill is needed. TeamFiltration is an open source M365 attack kit, built about five years ago and made public at DEF CON 30 in a talk titled "Taking a Dump in the Cloud" [2]. It enumerates a tenant's accounts and brute-forces them while rotating infrastructure to avoid IP blocking, and it automates exfiltration and backdooring across connected Microsoft applications [3]. The actor paired it with basic credential spraying [15]. According to Dark Reading's report on the research, the breakthrough involved no new tool or tactic [11].

Seven accounts out of more than 5,700 is at most about 0.12 percent [1]. All seven were functional or service accounts set up for tasks like managing tickets and approving vendor payments. None had active user history. Nobody had logged into them or used them to perform an action [7].

Six of them fell within seven minutes, roughly one every 70 seconds [8][2]. Dark Reading describes default or shared credentials and missing MFA as likely, based on that speed [8]. The report does not say which roles the seven accounts held. That leaves open whether the attacker's reach into the M365 management and Azure portals came straight from an over-permissioned service account or from a later step [10].

Yaniv Miron, director of threat research at Proofpoint, said UNK_CondorFiltration's victim is hardly unique [14]. At any given organization, he said, "a lot of service accounts are being created for different purposes. Then when that purpose is no longer needed, nobody's making sure that user is locked out or disabled." [12] He also said: "Sometimes accounts are being created not in any official way, by teams that don't officially document it." [13]

Closing this particular gap costs little. An account that has never performed an action can be disabled without breaking a process that depends on it [7]. The same empty history gives defenders a clean signal, because any sign-in to such an account is its first. Miron's second point is the expensive one. Accounts that teams create without documentation have to be found before anyone can disable them [13].

The published evidence covers one actor using one public tool over roughly a month [3]. It started with volume against financial institutions and then concentrated on a single retailer, and every account it is reported to have taken came in that concentrated wave [4][5]. Proofpoint describes the actor as previously unknown [1].

What to watch

  • Whether Proofpoint publishes indicators for UNK_CondorFiltration or links it to intrusions beyond the four Chilean targets described.
  • Whether the retailer discloses what roles the seven accounts held and what the attacker did in the Azure portal, including any TeamFiltration backdoors left behind.
  • A fourth wave against a new Chilean sector, which would show the actor is still widening its target list after the retailer.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories