# A password-spraying campaign across 5,700 accounts found its way in through seven service accounts on default passwords

Source: https://startwithidentity.com/blog/2026-09-24-teamfiltration-spraying-found-seven-service-accounts-on-default-passwords/
Last updated: 2026-09-24
License: content by Start with Identity. Cite the source URL.

---

[Proofpoint](https://startwithidentity.com/vendors/itdr/proofpoint/) detailed a campaign it tracks as UNK_CondorFiltration that used TeamFiltration, an open-source framework for enumerating, spraying and backdooring [Entra ID](https://startwithidentity.com/vendors/iam/microsoft-entra/) accounts, against more than 5,700 accounts in 28 Microsoft 365 tenants, mostly Chilean retail and financial organizations. It ran in three waves between July 21 and August 16, from 1,487 AWS EC2 addresses, peaking at about 1,560 accounts in a day. Seven accounts were compromised. All seven were unmanaged functional or service accounts, not employee accounts, and all used default or unrotated passwords with no MFA. Within two minutes of access the attacker switched to a VPN node in Germany, opened Office, OneDrive and Teams, probed the corporate VPN, Azure Portal and SharePoint Online, and began requesting Microsoft Graph tokens. TeamFiltration was also behind a 2025 campaign that targeted more than 80,000 accounts.

## Why it matters

Password spraying is supposed to be a solved problem in a tenant with MFA everywhere. This campaign shows where "everywhere" stops: shared mailboxes, kiosk logins, integration accounts and other identities no single person owns, which keep the password they were created with and are exempted from MFA because nobody is there to answer the prompt. Out of 5,700 accounts tried, those were the only ones that opened.

The fix is an inventory question more than a technology one. List every account in Entra ID that can sign in interactively but has no named owner, then decide for each whether it needs to sign in at all. Most functional accounts do not, and Conditional Access can block interactive sign-in for them outright; the ones that do need an owner, a rotated password and a phishing-resistant method. The fast pivot to Graph token requests is the detection opportunity: a functional account asking for new tokens from a new network is rarely legitimate. See [password spraying](https://startwithidentity.com/techniques/password-spraying/) and [service accounts](https://startwithidentity.com/glossary/service-account/).

Source: [The Hacker News](https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html)
