TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
A recent TeamFiltration campaign has compromised seven Microsoft 365 accounts using default passwords. The attack, codenamed UNK_CondorFiltration, targeted over 5,700 accounts across 28 Microsoft 365 tenants.
The majority of the targeted accounts belonged to Chilean retail and financial institutions, with one unnamed retailer facing 78.3% of all observed authentication events. The campaign unfolded in three waves between late July and August 2026, with a peak of approximately 1,560 accounts targeted on August 15.
According to Proofpoint, the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams that were never rotated. Six of the seven compromised accounts were broken into within 7 minutes, suggesting shared or default passwords rather than individually targeted credential stuffing.