Proofpoint Details M365 Attacks on Chilean Firms via Neglected Service Accounts
Proofpoint researchers presented findings at Protect 2026 describing a threat actor, tracked as UNK_CondorFiltration, that has been targeting Microsoft 365 environments in Chile since July 21. Using the open-source TeamFiltration toolkit and credential spraying, the attacker did not compromise any human employee accounts but instead broke in through neglected non-human machine and service accounts, gaining access to sensitive data.
GoKawiil's interpretation of the reporting above, not reported fact.
The campaign highlights a common blind spot in enterprise identity security: non-human accounts for apps and automated processes often retain default credentials and excessive permissions because no single person is responsible for maintaining them. Because the attacker used a widely available open-source tool rather than custom malware, similar low-effort intrusions could plausibly be replicated against other organizations that fail to audit machine identities, suggesting a broader exposure beyond Chile.
- Proofpoint identified a new threat actor, UNK_CondorFiltration, targeting M365 accounts in Chile since July 21.
- The attacker used the open-source TeamFiltration toolkit and credential spraying, succeeding only against non-human service accounts, not employee logins.
- The incident underscores the risk of poorly monitored machine and application identities within Microsoft 365 environments.
YubiKey 5 NFC Security Key — This article highlights how neglected non-human accounts with weak or default credentials became a gateway for attackers into M365 environments. Hardware security keys like the YubiKey enforce strong phishing-resistant authentication for service and admin accounts, making credential spraying attacks far harder to pull off. It's a practical step toward closing the exact kind of identity gaps described in this breach.》
See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: darkreading.com — Nate Nelson, 2026-09-24
Published there as: “Ghost Service Accounts Enable M365 Data Theft in Chile”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.