$ techbeacon▋
Breaches

Hackers Exploit Over 5,700 Microsoft 365 Accounts Using Unprotected Service Accounts

Hackers Exploit Over 5,700 Microsoft 365 Accounts Using Unprotected Service Accounts

Security researchers have uncovered a coordinated campaign that compromised more than 5,700 Microsoft 365 accounts spread across 28 separate tenant environments. The attackers relied on a password‑spraying technique that specifically targeted dormant service accounts that had never been configured with multi‑factor authentication (MFA).

The operation, catalogued by cybersecurity firm Proofpoint under the label UNK_CondorFiltration, employed a low‑and‑slow credential‑guessing approach. By repeatedly trying common passwords against a large list of usernames, the threat actors avoided triggering typical account lockout mechanisms while eventually gaining access to a subset of accounts.

Out of the thousands of accounts probed, seven service accounts were successfully breached. These accounts, often created for automated processes or legacy applications, had been left active but unused, and crucially, they lacked any form of MFA protection. Without the additional verification step, the attackers were able to log in and potentially leverage the accounts for further malicious activity within the compromised tenants.

The campaign showed a pronounced focus on organizations operating in Chile, suggesting either a regional motive or that the attackers possessed specific knowledge of credential patterns used by Chilean entities. While the exact intent remains under investigation, the targeting of service accounts hints at an effort to gain persistent footholds that are harder to detect than typical user logins.

Experts warn that the breach of service accounts can have cascading effects, as such accounts often hold elevated privileges or access to integration points between systems. Unauthorized entry could enable data extraction, the deployment of ransomware, or the creation of additional backdoors for future intrusions.

Microsoft has issued guidance urging administrators to audit all service accounts, deactivate those that are no longer needed, and enforce MFA wherever possible. The company also recommends implementing conditional access policies, monitoring sign‑in anomalies, and employing password‑less authentication methods to reduce reliance on static credentials.

The incident underscores a broader industry challenge: legacy accounts that escape regular security reviews become attractive targets for opportunistic attackers. Security teams are advised to incorporate continuous discovery of inactive identities into their hygiene routines and to apply zero‑trust principles that limit the blast radius of any single compromised credential.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related