Ghost Service Accounts Enable M365 Data Theft in Chile

Ghost Service Accounts Enable M365 Data Theft in Chile

In a stark reminder that even the most robust security measures can be undermined by human error, hackers have been exploiting forgotten and lost machine accounts in Microsoft 365 (M365) to steal sensitive data from organizations in Chile. This brazen tactic has left many wondering how such a seemingly simple vulnerability could go unnoticed for so long.

At the heart of this issue lies the concept of nonhuman accounts – essentially, service accounts that are created for applications and automated processes, but often fall out of focus as they sit dormant. These accounts typically come with default credentials and excessive permissions, making them ripe for exploitation if not properly maintained or secured. The problem is further exacerbated by the fact that these accounts are often overlooked in favor of focusing on employee identities.

Researchers at Proofpoint unveiled a threat actor attempting to breach M365 environments in Chile using an open-source toolkit called TeamFiltration, which allows hackers to brute-force nonhuman accounts and gain access to sensitive data. The tool, developed five years ago, uses basic credential spraying to enumerate accounts within a tenant and then facilitate broad data exfiltration and backdooring across connected Microsoft applications.

The threat actor, tracked as UNK_CondorFiltration, began probing hundreds of M365 accounts associated with two major banking institutions in Chile on July 21. However, it wasn’t until mid-August that the group successfully compromised seven corporate accounts at a major retailer by identifying forgotten service accounts with default credentials and no multifactor authentication protection.

In each case, the attackers bypassed employee accounts, which had been properly secured, and instead exploited nonhuman accounts with little to no active user history. The team used TeamFiltration’s auto-exfiltration function to pull sensitive data from Outlook, Teams, OneDrive, and even accessed the company’s virtual private network (VPN) to browse SharePoint files.

This campaign serves as a stark reminder that even the most robust security measures can be undermined by human error. “A lot of service accounts are being created for different purposes, but nobody keeps track of them,” says Yaniv Miron, director of threat research at Proofpoint. “These accounts often contain default or shared credentials with excessive permissions, making them a ticking time bomb waiting to be exploited.”

As organizations continue to rely on cloud services like M365, it’s essential that they prioritize the security and maintenance of nonhuman accounts. This includes regular audits to identify and remediate forgotten service accounts, implementing multifactor authentication (MFA) protection, and ensuring proper credential management.

Ultimately, this incident highlights the importance of a holistic approach to cybersecurity – one that goes beyond focusing solely on employee identities and acknowledges the potential vulnerabilities hidden within nonhuman accounts. By doing so, organizations can better protect themselves against these types of attacks and prevent sensitive data from falling into the wrong hands.


Source: Dark Reading — 2026-09-24