A password-spraying campaign across 5,700 accounts found its way in through seven service accounts on default passwords
Proofpoint tracked a TeamFiltration campaign against 28 Microsoft 365 tenants in Chile. It sprayed more than 5,700 accounts and compromised seven, every one an unmanaged functional or service account on a default or unrotated password with no MFA.
Proofpoint detailed a campaign it tracks as UNK_CondorFiltration that used TeamFiltration, an open-source framework for enumerating, spraying and backdooring Entra ID accounts, against more than 5,700 accounts in 28 Microsoft 365 tenants, mostly Chilean retail and financial organizations. It ran in three waves between July 21 and August 16, from 1,487 AWS EC2 addresses, peaking at about 1,560 accounts in a day. Seven accounts were compromised. All seven were unmanaged functional or service accounts, not employee accounts, and all used default or unrotated passwords with no MFA. Within two minutes of access the attacker switched to a VPN node in Germany, opened Office, OneDrive and Teams, probed the corporate VPN, Azure Portal and SharePoint Online, and began requesting Microsoft Graph tokens. TeamFiltration was also behind a 2025 campaign that targeted more than 80,000 accounts.
Why it matters
Password spraying is supposed to be a solved problem in a tenant with MFA everywhere. This campaign shows where "everywhere" stops: shared mailboxes, kiosk logins, integration accounts and other identities no single person owns, which keep the password they were created with and are exempted from MFA because nobody is there to answer the prompt. Out of 5,700 accounts tried, those were the only ones that opened.
The fix is an inventory question more than a technology one. List every account in Entra ID that can sign in interactively but has no named owner, then decide for each whether it needs to sign in at all. Most functional accounts do not, and Conditional Access can block interactive sign-in for them outright; the ones that do need an owner, a rotated password and a phishing-resistant method. The fast pivot to Graph token requests is the detection opportunity: a functional account asking for new tokens from a new network is rarely legitimate. See password spraying and service accounts.
Source: The Hacker News
Related on Start with Identity
- BlogEntra ID stops delivering SMS and voice codes on February 1, and global admins go last
From February 1, 2027, Microsoft stops providing SMS and voice authentication in Entra ID, and users with no other method must register a passkey to keep signin
- BlogA CVSS 10.0 Metabase zero-day handed admin access through the password reset endpoint
CVE-2026-72898 lets an unauthenticated attacker inject SQL through Metabase's password reset endpoint and take administrative control. It was exploited as a zer
- BlogJadePuffer used a service principal leaked in a GitHub issue to wipe Azure resources in seven minutes
Microsoft says the operator it tracks as Storm-3168 used two compromised service principals and an AI-driven toolchain to map an Azure tenant, pull storage keys
- GuideKubernetes Identity and Security Guide: RBAC, Service Accounts, and Pod Identity
Secure Kubernetes workloads with proper RBAC configuration, service account hardening, OIDC integration, pod identity, and secrets management best practices.
- GlossaryPassword Spraying
Trying a few common passwords across many accounts to avoid lockouts. Effective against weak password policies and accounts without MFA. Spraying is designed to
- ArticleSecuring Service Accounts: A Complete Best Practices Guide
Complete best practices for managing service accounts, tackling sprawl, lifecycle management, credential rotation, monitoring, and achieving zero standing privi