Skip to content

Security1 publisher2 min readPublished

A 5,700-account Microsoft 365 spray in Chile broke only unrotated service accounts

Proofpoint tracked three waves of TeamFiltration password spraying against Microsoft 365 tenants in Chile between July 21 and August 16. The seven accounts that opened were all functional identities carrying provisioned passwords with no MFA.

The Watch · Security desk

Photograph accompanying A 5,700-account Microsoft 365 spray in Chile broke only unrotated service accounts
Photo: esecurityplanet.com

What happened

  • Proofpoint says an active TeamFiltration campaign it tracks as UNK_CondorFiltration targeted more than 5,700 accounts across 28 Microsoft 365 tenants, mostly Chilean retail and financial institutions.
  • Three waves of spraying ran between July 21 and August 16, 2026, the last of them peaking near 1,560 accounts on August 15 against a major Chilean retailer and producing seven compromises.
  • Every account that was broken into was an unmonitored service or functional identity still carrying a default or unrotated password with no MFA enforced on it.
  • Under two minutes after a successful login, the operator pivoted to a German VPN node. From there it probed the retailer's VPN SAML endpoint, opened Azure Portal, browsed SharePoint Online and requested Microsoft Graph API tokens.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The reachable part of the identity perimeter is the set every MFA rollout skipped: non-human accounts that sit outside the password rotation rules.
  • capability An operator needs no novel implant to do this. The only real constraint is finding one unrotated credential. The defensive work belongs to identity inventory, not malware detection.
  • decision The retailer has to decide whether to notify on access evidence alone, because the telemetry shows which mailboxes and sites were opened and not what left them.
  • precedent This is the second cluster Proofpoint has named around the same framework since June 2025. Spraying Entra ID tenants from cloud provider address space is a standing method.

Seven compromises against more than 5,700 targeted accounts is a success rate of about 0.12 percent [1]. The spraying came from 1,487 unique AWS EC2 source addresses over 27 days [3][2], and one unnamed Chilean retailer absorbed 78.3 percent of the authentication events Proofpoint observed [5].

Six of the seven accounts were broken within seven minutes [11]. Proofpoint attributes that speed to a shared or default password set, and says it was not credential stuffing with individually harvested passwords [11]. The earlier waves were larger and produced nothing: roughly 100 to 120 unique accounts a day against two major Chilean banking institutions between July 21 and 24 [6], then a peak near 1,520 accounts on July 27 against another financial institution before the volume dropped [7].

No individual employee account was compromised [4]. Users in those tenants are required to change passwords periodically, according to Proofpoint. The dormant functional accounts were provisioned to run business operations and then left unmonitored with their original credentials [9]. "It is the forgotten account," Proofpoint said in a statement. "Service accounts provisioned for convenience and never revisited are a structurally unprotected attack surface." [16]

The tooling is public. TeamFiltration is a legitimate cross-platform offensive framework for "enumerating, spraying, exfiltrating, and backdooring" Entra ID accounts. It gives an operator email validation, password testing across enumerated accounts, data harvesting and covert interactive access to OneDrive [12]. Proofpoint documented a different cluster using the same framework in June 2025, UNK_SneakyStrike, against more than 80,000 accounts across hundreds of organizations' cloud tenants [15]. This target list is about 7 percent of that size [3], narrowed onto Chilean retail and finance [2].

On most of the compromised accounts the operator signed into Microsoft Office, OneDrive and Teams, which Proofpoint says may indicate data harvesting [13]. Sign-in events alone cannot be taken as evidence of exfiltration, the company said [13]. The campaign account comes from Proofpoint, and the targeted organizations are not named [1].

What to watch

  • Whether the unnamed Chilean retailer confirms data loss, or whether the case stays bounded by sign-in telemetry.
  • Whether the same EC2 source ranges reappear against tenants outside Chile. That would widen this from a regional campaign to a general one.
  • Whether Microsoft restricts password-only sign-in for service principals and legacy functional accounts in Entra ID defaults.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories