Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Accounts Breached in Major Cyber Campaign

Microsoft 365 Accounts Breached in Major Cyber Campaign

Posted on September 24, 2026 By CWS

Cybersecurity experts have revealed a significant threat campaign, identified as UNK_CondorFiltration, which has targeted over 5,700 accounts within 28 Microsoft 365 environments. This operation has primarily affected retail and financial sectors in Chile, originating from 1,487 distinct AWS EC2 IP addresses, according to research by Proofpoint.

Focus on Chilean Institutions

The campaign’s main targets were Chilean retail and financial entities. It exploited a critical security gap by compromising seven accounts, which were primarily service accounts with default or unrotated passwords, lacking multi-factor authentication (MFA). These accounts are often overlooked and remain unmonitored, making them vulnerable to such attacks.

The attack unfolded in three waves from late July to August 2026. Notably, an unnamed Chilean retailer bore the majority of the attack, with 78.3% of authentication events targeting it. The campaign’s phases included:

  • July 21-24: Targeting 100-120 accounts daily against two major Chilean banks.
  • July 26-28: Peaking at 1,520 accounts on July 27, focusing on another financial institution.
  • August 13-16: Reaching 1,560 accounts on August 15, aimed at a major retailer, resulting in seven compromises.

Technical Insights and Methods

The threat actor utilized TeamFiltration, a legitimate cross-platform offensive framework, to execute the attack. This tool allows for the enumeration, password spraying, and backdooring of Entra ID accounts. It facilitated the validation of email accounts, testing of common passwords, and covert access to OneDrive.

Most compromised accounts granted access to Microsoft Office, OneDrive, and Teams, suggesting potential data exfiltration. However, sign-in activities alone do not confirm data theft. The attackers swiftly pivoted their operations, utilizing a German VPN node to access corporate VPNs, Azure Portals, and SharePoint Online.

Broader Implications and Historical Context

The UNK_CondorFiltration is not an isolated incident. In June 2025, the TeamFiltration framework was also employed in another campaign, UNK_SneakyStrike, targeting over 80,000 user accounts across various cloud tenants. These incidents underline the persistent vulnerability of unmonitored service accounts.

Proofpoint emphasizes that the weakest link in enterprise security may not be a vulnerable employee or zero-day exploit but rather forgotten, unmonitored accounts. These service accounts, often left with default credentials, represent an unprotected attack surface within the digital infrastructure.

The recent breaches serve as a stark reminder of the need for robust cybersecurity measures, including regular password updates and stringent monitoring of all accounts, to protect against evolving threats in the digital landscape.

The Hacker News Tags:AWS EC2, Chilean institutions, cloud security, Cybersecurity, default passwords, identity security, Microsoft 365, Proofpoint, service accounts, TeamFiltration

Post navigation

Previous Post: Armenian Man Jailed for Role in Ryuk Ransomware
Next Post: Astrana Health Data Breach Exposes Sensitive Information

Related Posts

Linux Kernel Vulnerability Exposes Root Access Risk Linux Kernel Vulnerability Exposes Root Access Risk The Hacker News
Linux Rootkits and AI Intrusions: Key Security Threats Linux Rootkits and AI Intrusions: Key Security Threats The Hacker News
Linux AppArmor Vulnerabilities Risk Root Escalation Linux AppArmor Vulnerabilities Risk Root Escalation The Hacker News
AI Security Concerns in Amazon Bedrock and Other Platforms AI Security Concerns in Amazon Bedrock and Other Platforms The Hacker News
Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers The Hacker News
Microsoft Warns of ‘Payroll Pirates’ Hijacking HR SaaS Accounts to Steal Employee Salaries Microsoft Warns of ‘Payroll Pirates’ Hijacking HR SaaS Accounts to Steal Employee Salaries The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft’s AI-Driven SOC Enhancements with SIEM Integration
  • Island Secures $400M Funding, Reaches $6.4B Valuation
  • New Android Spyware Targets Logistics Sector
  • NIST and CISA/FBI Issue Crucial OT Security Updates
  • ClickFix: How Trusted Sites Become Malware Traps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft’s AI-Driven SOC Enhancements with SIEM Integration
  • Island Secures $400M Funding, Reaches $6.4B Valuation
  • New Android Spyware Targets Logistics Sector
  • NIST and CISA/FBI Issue Crucial OT Security Updates
  • ClickFix: How Trusted Sites Become Malware Traps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark