A previously unknown threat actor has been exploiting a common security blind spot in Microsoft 365 (M365) environments to steal enterprise data from organizations in Chile. The attackers have been using a technique called TeamFiltration, an open-source toolkit that allows them to gain access to sensitive information without breaching employee accounts.
According to researchers at Proofpoint, the threat actor, dubbed UNK_CondorFiltration, has been targeting M365 environments for months, probing hundreds of accounts associated with major banking institutions and a retailer in Chile. While the initial attacks were unsuccessful, the group eventually identified seven forgotten service accounts that had been created for business functions such as managing tickets or approving vendor payments.
These nonhuman accounts, which belonged to applications and automated processes rather than employees, had default or shared credentials and no multifactor authentication (MFA) protection. The attackers compromised six of these accounts in just seven minutes, using TeamFiltration’s auto-exfiltration function to pull emails, chat conversations, and files from Outlook, Teams, and OneDrive.
The breach was not limited to data exfiltration. In at least one case, the attacker probed the company’s virtual private network (VPN), accessing both its M365 management portal and the Azure portal from which it manages its cloud services. The threat actor also browsed SharePoint files, demonstrating a level of sophistication that suggests they are highly motivated to exploit these vulnerabilities.
According to Yaniv Miron, director of threat research for Proofpoint, this type of attack is not unique to Chile or even to M365 environments. “A lot of service accounts are being created for different purposes within an organization,” he explains, “but often they fall out of focus and become forgotten relics with excessive permissions.” This creates a security blind spot that can be exploited by attackers.
The ease with which UNK_CondorFiltration compromised these service accounts highlights the importance of regularly reviewing and securing all accounts within an M365 environment. Organizations should prioritize identifying and limiting access to nonhuman accounts, implementing strong authentication protocols, and monitoring for suspicious activity.
As a practical takeaway, we recommend that organizations review their M365 environments to identify any forgotten or inactive service accounts. These should be secured with strong passwords, MFA, and regular audits to ensure they are up-to-date. By closing this security gap, organizations can significantly reduce the risk of data theft and other types of cyber attacks.
Source: Dark Reading — 2026-09-24