TeamFiltration Hackers Exploit Forgotten Microsoft 365 Service Accounts
A team of hackers known as TeamFiltration exploited forgotten Microsoft 365 service accounts to gain cloud access. The attacks targeted thousands of Microsoft 365 accounts, with weak passwords and no multi-factor authentication (MFA) allowing the attackers to succeed.
According to Proofpoint, a cybersecurity firm that tracked the campaign, the hackers used TeamFiltration to target 5,714 accounts across 28 Microsoft 365 tenants. The majority of these accounts were located in Chile.
The compromised accounts were functional or service accounts with no prior legitimate sign-in activity. These types of accounts are often created for specific tasks such as ticket management or vendor payments, but they can remain active without being properly secured.
Proofpoint observed 32,825 authentication events from 1,487 AWS EC2 source IPs during the campaign. The hackers used the Teams API to enumerate Microsoft 365 accounts and automate access to email, Teams, OneDrive, SharePoint, and Microsoft Graph data after a successful sign-in.