Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords: A Critical Exposure Gap Revealed


TeamFiltration, a malicious campaign, compromised seven Microsoft 365 accounts using default passwords, highlighting a critical exposure gap around forgotten, non-human identities. By implementing robust identity and access management practices, organizations can reduce the risk of compromise and protect their sensitive data.

  • TeamFiltration, a malicious campaign, compromised 7 Microsoft 365 accounts using default passwords.
  • The campaign targeted over 5,700 accounts across 28 Microsoft 365 tenants, primarily focusing on Chilean retail and financial institutions.
  • The attack used default passwords, including credentials provisioned by IT teams and never rotated.
  • Service accounts with default passwords were the primary targets of the campaign, with 6 out of 7 compromised accounts being broken into within 7 minutes.
  • The use of TeamFiltration highlights the importance of implementing robust identity and access management practices, including regular password rotation and MFA.
  • The campaign serves as a wake-up call for organizations to review their identity and access management practices and implement robust monitoring systems to detect potential security threats.



  • The cybersecurity landscape is ever-evolving, with new threats and vulnerabilities emerging on a daily basis. Recently, a malicious campaign known as TeamFiltration has made headlines, compromising seven Microsoft 365 accounts using default passwords. This malicious activity highlights a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no multi-factor authentication (MFA).

    According to Proofpoint, a leading enterprise security company, the TeamFiltration campaign targeted over 5,700 accounts across 28 Microsoft 365 tenants. The activity primarily focused on Chilean retail and financial institutions, with one unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events. The campaign unfolded across three different waves, with the first wave occurring from late July to August 2026, targeting approximately 100-120 unique accounts per day and directed against two major Chilean banking institutions.

    The second wave targeted a peak of about 1,520 accounts on July 27, directed against another major Chilean financial institution. The third wave, which occurred from August 13-16, targeted a peak of about 1,560 accounts on August 15, directed against a major Chilean retailer, leading to seven account compromises. Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated.

    These service accounts, which were provisioned to run business operations and then left unmonitored, were the primary targets of the TeamFiltration campaign. Every successful compromise was linked to unmonitored service accounts with a default password. Six of the seven compromised accounts were broken into within 7 minutes, likely indicating a shared or default password set rather than individually targeted credential stuffing.

    The activity is characterized by the use of TeamFiltration, a legitimate cross-platform offensive framework designed for "enumerating, spraying, exfiltrating, and backdooring" Entra ID accounts. This framework allows an operator to validate email accounts, test common or targeted passwords across enumerated accounts, harvest sensitive data, and gain covert, interactive access to OneDrive. Across most of the compromised accounts, the threat actor leveraged the foothold to access Microsoft Office, OneDrive, and Teams, potentially indicative of data harvesting and exfiltration.

    The use of TeamFiltration highlights a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA. As Proofpoint noted, "The UNK_CondorFiltration campaign is a reminder that one of the weakest links in an enterprise identity perimeter is often not a phished employee or a zero-day exploit. It is the forgotten account. Service accounts provisioned for convenience and never revisited are a structurally unprotected attack surface."

    This incident serves as a wake-up call for organizations to review their identity and access management practices, ensuring that default passwords are regularly rotated and MFA is implemented for all accounts. By doing so, organizations can reduce the risk of compromise and protect their sensitive data.

    The TeamFiltration campaign also highlights the need for organizations to monitor their accounts and identify potential vulnerabilities. As the threat actor was able to compromise seven accounts in a short period, it is essential for organizations to implement robust monitoring systems to detect potential security threats.

    In conclusion, the TeamFiltration campaign is a critical reminder of the importance of implementing robust identity and access management practices. By regularly rotating default passwords and implementing MFA, organizations can reduce the risk of compromise and protect their sensitive data.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/TeamFiltration-Campaign-Compromises-Seven-Microsoft-365-Accounts-Using-Default-Passwords-A-Critical-Exposure-Gap-Revealed-ehn.shtml

  • https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html


  • Published: Thu Sep 24 03:45:51 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us