INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
TeamFiltration Compromises Seven Microsoft 365 Accounts with Default Passwords
| 2026-09-24 06:32 LOW HIGH DATA BREACH
Executive Summary
AI-generated
A TeamFiltration campaign, codenamed UNK_CondorFiltration, has compromised seven Microsoft 365 accounts using default passwords in Chile between late July and August 2026. The attackers primarily targeted dormant service accounts provisioned to run business operations but left unmonitored, with six of the seven compromised accounts breached within 7 minutes. The campaign originated from 1,487 unique AWS EC2 source IP addresses and leveraged TeamFiltration, a legitimate cross-platform framework for enumerating, spraying, exfiltrating, and backdooring Entra ID accounts. Affected entities include Chilean retail and financial institutions, with one major retailer facing the brunt of authentication events. The attackers accessed Microsoft Office, OneDrive, Teams, Azure Portal, SharePoint Online, and initiated Microsoft Graph API token requests after gaining foothold in compromised accounts.
Technical Mitigations AI-generated
• Patch default passwords for unmanaged functional or service accounts using Microsoft 365's built-in password rotation feature.
• Monitor and rotate default passwords for IT-provisioned credentials, especially those never rotated.
• Implement multi-factor authentication (MFA) on all managed identities to prevent unauthorized access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
DACH
DACH
financefinance
retailretail
Incident Timeline
August 13-16
Threat actors used default passwords to target approximately 1,560 Microsoft 365 accounts at a major Chilean retailer between August 13 and 16.
Click on any entity below to view its context and source!
target_region
Chile
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
infrastructure
Microsoft 365
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
365 Microsoft
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
78.3 %
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,520 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,560 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
July 21-24
Threat actors used default passwords to target approximately 100–120 unique Microsoft 365 accounts per day across three waves from late July to August 2026.
Click on any entity below to view its context and source!
target_region
Chile
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
infrastructure
Microsoft 365
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
365 Microsoft
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
78.3 %
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,520 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,560 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
June 2025
Threat actors used the open-source penetration testing framework to target over 80,000 user accounts across hundreds of organizations' cloud tenants in June 2025.
Click on any entity below to view its context and source!
victims
80,000 user
In June 2025, Proofpoint detailed another threat cluster dubbed
UNK_SneakyStrike
that targeted over 80,000 user accounts across hundreds of organizations' cloud tenants using the open-source penetration testing framework.
July 27
Threat actors used default passwords to target approximately 1,520 Microsoft 365 accounts on July 27.
Click on any entity below to view its context and source!
target_region
Chile
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
infrastructure
Microsoft 365
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
365 Microsoft
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
78.3 %
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,520 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,560 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
August 2026
Threat actors compromised seven Microsoft 365 accounts using default passwords, gaining access to various services and potentially harvesting data.
Click on any entity below to view its context and source!
organisation
Microsoft Office
Across most of the compromised accounts, the threat actor leveraged the foothold to access Microsoft Office, OneDrive, and Teams, potentially indicative of data harvesting and exfiltration.
organisation
Teams
Across most of the compromised accounts, the threat actor leveraged the foothold to access Microsoft Office, OneDrive, and Teams, potentially indicative of data harvesting and exfiltration.
organisation
OneDrive
It allows an operator to validate email accounts, test common or targeted passwords across enumerated accounts, harvest sensitive data, and gain covert, interactive access to OneDrive.
organisation
SharePoint Online
Less than 2 minutes after successful compromise, the operator has been observed pivoting to a German VPN node to probe the corporate VPN ("vpn.[redacted].cl/SAML20/SP"), access Azure Portal, browse SharePoint Online, and initiate Microsoft Graph API token requests.
organisation
Microsoft Graph API
Less than 2 minutes after successful compromise, the operator has been observed pivoting to a German VPN node to probe the corporate VPN ("vpn.[redacted].cl/SAML20/SP"), access Azure Portal, browse SharePoint Online, and initiate Microsoft Graph API token requests.
August 15
Threat actors sprayed compromised Microsoft 365 accounts with default passwords, including those provisioned by IT teams and never rotated.
Click on any entity below to view its context and source!
target_region
Chile
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
infrastructure
Microsoft 365
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
365 Microsoft
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
78.3 %
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,520 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,560 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
Sep 24, 2026
Threat actors used 1,487 unique AWS EC2 source IP addresses to target seven Microsoft 365 accounts using default passwords.
Click on any entity below to view its context and source!
organisation
MFA
"The campaign compromised 7 accounts – all of which were unmanaged functional or service accounts rather than individual employee accounts – highlighting a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA
organisation
IP
It originated from 1,487 unique AWS EC2 source IP addresses.
infrastructure
1,487 source IP addresses
It originated from 1,487 unique AWS EC2 source IP addresses.
late July to August 2026
Threat actors used default passwords to target approximately 100–120 unique Microsoft 365 accounts per day across three waves from late July to August 2026.
Click on any entity below to view its context and source!
target_region
Chile
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
infrastructure
Microsoft 365
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
365 Microsoft
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
78.3 %
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,520 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,560 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
2026/09/24
Threat actors using the TeamFiltration campaign codenamed UNK_CondorFiltration compromised seven Microsoft 365 accounts by exploiting default passwords.
Click on any entity below to view its context and source!
infrastructure
Microsoft 365
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords.
Ravie Lakshmanan
Sep 24, 2026
Cloud Security / Identity Security
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed
UNK_CondorFiltration
that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.
organisation
TeamFiltration Campaign Compromises
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords.
organisation
TeamFiltration
Ravie Lakshmanan
Sep 24, 2026
Cloud Security / Identity Security
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed
UNK_CondorFiltration
that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.
organisation
Microsoft
Ravie Lakshmanan
Sep 24, 2026
Cloud Security / Identity Security
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed
UNK_CondorFiltration
that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.
July 26-28
Threat actors used default passwords to target approximately 1,520 Microsoft 365 accounts on July 27.
Click on any entity below to view its context and source!
target_region
Chile
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
infrastructure
Microsoft 365
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
365 Microsoft
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
78.3 %
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,520 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
general_metric
1,560 accounts
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
Tactical Metrics
Metrics
infrastructure
Microsoft Office
Affected Product
Click for context!
Across most of the compromised accounts, the threat actor leveraged the foothold to access Microsoft Office, OneDrive, and Teams, potentially indicative of data harvesting and exfiltration.
Metrics
infrastructure
Microsoft 365
Affected Product
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords.
Ravie Lakshmanan
Sep 24, 2026
Cloud Security / Identity Security
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed
UNK_CondorFiltration
that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.
The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -
July 21-24, targeting approximately 100–120 unique accounts per day and directed against two major Chilean banking institutions
July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution
August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises
Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.
Metrics
infrastructure
1,487
Source Ip Addresses
It originated from 1,487 unique AWS EC2 source IP addresses.
Metrics
victims
80,000
User
In June 2025, Proofpoint detailed another threat cluster dubbed
UNK_SneakyStrike
that targeted over 80,000 user accounts across hundreds of organizations' cloud tenants using the open-source penetration testing framework.
Intelligence Sources
The Hacker News
2026-09-24
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:55
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
Microsoft Office
entity
9x
timeline
Temporal Reference
Sep 24, 2026
date
3x
general metric
Accounts
5,700
accounts
2x
target region
Target Country
Chile
country
2x
tactic
Cyber Operation Type
Credential Stuffing
tactic
2x
general metric
Minutes
7
minutes
2x
infrastructure
Affected Product
Microsoft Office
software
Contextual Telemetry
Context Block
7 METRICS
industry
Targeted Sector
Retail
sector
general metric
Microsoft
365
microsoft
general metric
Sep
24
sep
general metric
Tenants
28
tenants
general metric
%
78
%
infrastructure
Source Ip Addresses
1,487
source ip addresses
victims
User
80,000
user
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.