TeamFiltration Exploits Default Passwords to Breach Thousands of Microsoft 365 Accounts in Chile
Security researchers have uncovered an active intrusion campaign that leveraged the open‑source TeamFiltration framework to compromise more than 5,700 Microsoft 365 accounts spread across 28 tenant organizations. The operation, tracked by Proofpoint under the internal name UNK_CondorFiltration, has concentrated on entities in Chile’s retail and financial sectors, where it has repeatedly accessed user mailboxes and other cloud services.
The attackers’ methodology hinges on exploiting accounts that still retain factory‑set or otherwise weak passwords. By automating credential‑spraying attempts against known default credentials, the TeamFiltration tool can gain a foothold without triggering many of the typical anomaly‑based alerts that focus on high‑volume brute‑force attacks. Once inside, the actors appear to harvest email data, download documents and potentially use the compromised accounts for further phishing or lateral movement within the victim’s network.
Microsoft 365, now a core productivity platform for many businesses, offers built‑in protections such as conditional access policies and multi‑factor authentication (MFA). However, the campaign highlights a persistent gap: organizations that have not enforced MFA or have left default passwords unchanged remain vulnerable. Proofpoint’s analysis suggests that the majority of the targeted tenants had not applied mandatory password changes after initial account provisioning, a practice that is increasingly discouraged by both Microsoft and industry best‑practice guides.
The discovery follows a broader trend of threat actors turning to “low‑tech” credential attacks that can be scaled quickly across cloud environments. While high‑profile ransomware incidents often dominate headlines, the steady stream of credential‑spraying campaigns underscores the importance of basic hygiene measures. Experts recommend that administrators audit all newly created accounts, enforce strong password policies, and enable MFA wherever possible, especially for privileged or admin‑level accounts.
Proofpoint has alerted the affected organizations and shared indicators of compromise with Microsoft’s threat‑intelligence teams. Microsoft has issued guidance urging customers to review their authentication settings and to rotate any passwords that may have been set to defaults during onboarding. As the UNK_CondorFiltration campaign continues to probe for weak accounts, security teams are advised to monitor for anomalous sign‑in locations, unexpected mailbox access patterns, and repeated failed login attempts that may signal ongoing automated attacks.
While the current wave appears focused on Chile, the tactics employed are not region‑specific and could be replicated against any tenant that neglects basic credential safeguards. The incident serves as a reminder that even sophisticated cloud platforms are only as secure as the configurations and policies governing them. Continued vigilance, rapid credential rotation, and widespread MFA adoption remain the most effective defenses against this class of intrusion.
Comments (0)
Be the first to comment.
Join the discussion