Proofpoint has disclosed details of an active TeamFiltration campaign, dubbed UNK_CondorFiltration, that targeted more than 5,700 accounts across 28 Microsoft 365 tenants. The activity, originating from 1,487 unique AWS EC2 IP addresses, primarily focused on Chilean retail and financial institutions and unfolded in three waves between late July and August 2026.
The campaign resulted in seven account compromises, all of which were unmanaged functional or service accounts rather than individual employee accounts. According to Proofpoint, these accounts carried default or unrotated passwords and had no multi-factor authentication enabled. Six of the seven accounts were broken into within seven minutes, indicating a shared or default password set rather than targeted credential stuffing.
The attackers used TeamFiltration, a legitimate cross-platform offensive framework for enumerating, spraying, exfiltrating, and backdooring Entra ID accounts. After compromise, they accessed Microsoft Office, OneDrive, and Teams, and were observed pivoting to a VPN node, probing corporate VPN endpoints, accessing Azure Portal, and initiating Microsoft Graph API token requests. Proofpoint noted that sign-in events alone do not prove data exfiltration.
This is not the first use of TeamFiltration in the wild; a June 2025 campaign, UNK_SneakyStrike, targeted over 80,000 user accounts. Proofpoint frames the new campaign as a reminder that forgotten service accounts, provisioned for convenience and never revisited, represent a structurally unprotected attack surface in the enterprise identity perimeter.