Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Accounts Breached in Major Cyber Campaign

Microsoft 365 Accounts Breached in Major Cyber Campaign

Posted on September 24, 2026 By CWS

Cybersecurity experts have revealed a significant threat campaign, identified as UNK_CondorFiltration, which has targeted over 5,700 accounts within 28 Microsoft 365 environments. This operation has primarily affected retail and financial sectors in Chile, originating from 1,487 distinct AWS EC2 IP addresses, according to research by Proofpoint.

Focus on Chilean Institutions

The campaign’s main targets were Chilean retail and financial entities. It exploited a critical security gap by compromising seven accounts, which were primarily service accounts with default or unrotated passwords, lacking multi-factor authentication (MFA). These accounts are often overlooked and remain unmonitored, making them vulnerable to such attacks.

The attack unfolded in three waves from late July to August 2026. Notably, an unnamed Chilean retailer bore the majority of the attack, with 78.3% of authentication events targeting it. The campaign’s phases included:

  • July 21-24: Targeting 100-120 accounts daily against two major Chilean banks.
  • July 26-28: Peaking at 1,520 accounts on July 27, focusing on another financial institution.
  • August 13-16: Reaching 1,560 accounts on August 15, aimed at a major retailer, resulting in seven compromises.

Technical Insights and Methods

The threat actor utilized TeamFiltration, a legitimate cross-platform offensive framework, to execute the attack. This tool allows for the enumeration, password spraying, and backdooring of Entra ID accounts. It facilitated the validation of email accounts, testing of common passwords, and covert access to OneDrive.

Most compromised accounts granted access to Microsoft Office, OneDrive, and Teams, suggesting potential data exfiltration. However, sign-in activities alone do not confirm data theft. The attackers swiftly pivoted their operations, utilizing a German VPN node to access corporate VPNs, Azure Portals, and SharePoint Online.

Broader Implications and Historical Context

The UNK_CondorFiltration is not an isolated incident. In June 2025, the TeamFiltration framework was also employed in another campaign, UNK_SneakyStrike, targeting over 80,000 user accounts across various cloud tenants. These incidents underline the persistent vulnerability of unmonitored service accounts.

Proofpoint emphasizes that the weakest link in enterprise security may not be a vulnerable employee or zero-day exploit but rather forgotten, unmonitored accounts. These service accounts, often left with default credentials, represent an unprotected attack surface within the digital infrastructure.

The recent breaches serve as a stark reminder of the need for robust cybersecurity measures, including regular password updates and stringent monitoring of all accounts, to protect against evolving threats in the digital landscape.

The Hacker News Tags:AWS EC2, Chilean institutions, cloud security, Cybersecurity, default passwords, identity security, Microsoft 365, Proofpoint, service accounts, TeamFiltration

Post navigation

Previous Post: Armenian Man Jailed for Role in Ryuk Ransomware
Next Post: Astrana Health Data Breach Exposes Sensitive Information

Related Posts

ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks ConnectWise to Rotate ScreenConnect Code Signing Certificates Due to Security Risks The Hacker News
Malware Hidden in SVG Images Targets Developers Malware Hidden in SVG Images Targets Developers The Hacker News
Chrome 0-Day, Data Wipers, Misused Tools and Zero-Click iPhone Attacks Chrome 0-Day, Data Wipers, Misused Tools and Zero-Click iPhone Attacks The Hacker News
Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It The Hacker News
Weekly Cybersecurity Recap: Major Threats and Developments Weekly Cybersecurity Recap: Major Threats and Developments The Hacker News
Join Webinar to Combat Rapid AI Cyber Threats Join Webinar to Combat Rapid AI Cyber Threats The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Unveils 2026 Election Security Plan Amid Cyber Threats
  • AI’s Impact on SOC Efficiency and Alert Management
  • Kosovo National Admits Guilt in Rydox Cybercrime Case
  • File Notification Systems Leak User Data on Major OS
  • Bitget Loses $351.6M in Hacker Breach, Suspects North Korea

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Unveils 2026 Election Security Plan Amid Cyber Threats
  • AI’s Impact on SOC Efficiency and Alert Management
  • Kosovo National Admits Guilt in Rydox Cybercrime Case
  • File Notification Systems Leak User Data on Major OS
  • Bitget Loses $351.6M in Hacker Breach, Suspects North Korea

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark