Skip to content
Back to the blog
Credential theft September 24, 2026 · 1 min read

Forgotten service accounts open the door to data theft in Microsoft 365

Proofpoint has uncovered a campaign, dubbed UNK_CondorFiltration, that targeted more than 5,700 accounts across 28 organisations using Microsoft 365, mainly retailers and financial institutions in Chile. The attackers used TeamFiltration, a legitimate security testing tool, to mass-test default passwords from almost 1,500 different Amazon cloud IP addresses, in three waves between July and August 2026. Their target was not employee accounts but unmanaged service or functional accounts.

They broke into seven accounts, none of which had multi-factor authentication, and six of them fell within just seven minutes, a sign that they shared the same password. From there they accessed Office, OneDrive, Teams, SharePoint and even the Azure portal. The lesson is clear: even if a company protects its staff accounts well, a single forgotten service account without MFA and with a default password can compromise its entire Microsoft 365 environment.

Tip from Soporte Informático 360

Review every account in your Microsoft 365, including service, shared and old project accounts: disable the ones you don’t use, change default passwords and turn on MFA for all of them. Also watch for sign-ins to accounts that had been inactive for a while.

Source: The Hacker News. Summary prepared by our team for informational purposes.

Related service

RackLab for home users

We build compact home racks with a firewall, segmented network, VPN and backups.