Proofpoint Details M365 Attacks on Chilean Firms via Neglected Service Accounts
Proofpoint researchers presented findings at Protect 2026 describing a threat actor, tracked as UNK_CondorFiltration, that has been targeting Microsoft 365 environments in Chile since July 21. Using the open-source TeamFiltration toolkit and credential spraying, the attacker did not compromise any human employee accounts but instead broke in through neglected non-human machine and service accounts, gaining access to sensitive data.