"The campaign compromised 7 accounts – all of which were unmanaged functional or service accounts rather than individual employee accounts – highlighting a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA [multi-factor authentication]," Proofpoint said in a statement.
Scope of the UNK_CondorFiltration campaign
Proofpoint researchers say the TeamFiltration campaign, tracked as UNK_CondorFiltration, targeted more than 5,700 accounts across 28 Microsoft 365 tenants. The activity generated sign-ins from 1,487 unique AWS EC2 source IP addresses and resulted in seven confirmed account compromises. The campaign concentrated heavily on Chilean retail and financial institutions, with one unnamed Chilean retailer responsible for 78.3% of all observed authentication events.
Three waves, precise peaks, and targeted sectors
Proofpoint describes the operation unfolding in three discrete waves between late July and August 2026. Wave one ran July 21–24 and targeted roughly 100–120 unique accounts per day, directed at two major Chilean banking institutions. Wave two, July 26–28, peaked at about 1,520 accounts on July 27 and was directed at another major Chilean financial institution. Wave three, August 13–16, peaked at about 1,560 accounts on August 15 and was directed against a major Chilean retailer; it was during this third wave that the seven account compromises occurred.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTactics: TeamFiltration, password spraying, and dormant service accounts
Proofpoint links the activity to TeamFiltration, which the report describes as a legitimate, cross-platform offensive framework used to enumerate, spray, exfiltrate, and backdoor Entra ID accounts. According to the findings, the threat actor most likely sprayed accounts with default passwords, including credentials that had been provisioned by IT teams and never rotated. The campaign largely focused on dormant service or functional accounts rather than employee accounts — a distinction the vendor connects to password-rotation mandates for human users. Every successful compromise in Proofpoint's telemetry was associated with an unmonitored service account retaining a default password and lacking multi-factor authentication.
Post-compromise activity and evidence limits
Across most of the compromised accounts, the operator used the foothold to access Microsoft Office, OneDrive, and Teams, activities Proofpoint says are "potentially indicative of data harvesting and exfiltration." The report cautions, however, that sign-in events alone cannot be taken as definitive evidence of exfiltration. Proofpoint also observed rapid post-compromise behavior: six of the seven compromised accounts were broken into within seven minutes, suggesting a shared or default password rather than individually tailored credential stuffing. In less than two minutes after a successful compromise, the operator pivoted to a German VPN node, probed a corporate VPN endpoint ("vpn.[redacted].cl/SAML20/SP"), accessed the Azure Portal, browsed SharePoint Online, and initiated Microsoft Graph API token requests.
What this means for Chilean retailers, financial institutions, and IT/security teams
- Chilean retailers: The unnamed retailer absorbed the majority of authentication events (78.3%), highlighting how a single large tenant can attract concentrated automated activity. Retail organizations with numerous dormant service identities should expect to be scrutinized for unrotated credentials.
- Financial institutions: Two major Chilean banks and another major financial institution were explicit targets in different waves. Financial-sector operators will face pressure to account for non-human identities that remain on production directories with default credentials and no MFA.
- IT and security teams: Proofpoint frames the root exposure as "forgotten, non-human identities." For defenders, the campaign underscores the operational gap around service accounts provisioned for convenience and left unmonitored; every successful compromise in the dataset traced back to such an account.
The UNK_CondorFiltration campaign reiterates a point Proofpoint drew from earlier activity: TeamFiltration has been repurposed for malicious use before. In June 2025, Proofpoint documented another cluster, UNK_SneakyStrike, that targeted more than 80,000 user accounts across hundreds of cloud tenants using the same open-source framework. The current operation, routed through thousands of cloud-hosted IPs and exploiting default credentials on non-human accounts, leaves concrete follow-up questions for defenders: who owns every service identity, when were those credentials last rotated, and which accounts are monitored for anomalous sign-ins?
Original report: https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html




