#TeamFiltration
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html

#CyberSecurity #InfoSec
September 25, 2026 at 3:00 AM
Campaña TeamFiltration compromete siete cuentas de Microsoft 365 que utilizaban contraseñas predeterminadas. (Inglés)

Vía: @thehackernews.bsky.social
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
TeamFiltration targeted over 5,700 Microsoft 365 accounts across 28 tenants, compromising seven service accounts with default passwords.
thehackernews.com
September 25, 2026 at 12:53 AM
Proofpoint linked UNK_CondorFiltration to TeamFiltration, hitting 5,700+ Microsoft 365 accounts across 28 Latin America tenants. All 7 successful breaches involved dormant service accounts with weak passwords and no MFA. #Chile #Microsoft365 #Azure
Spraying In The Andes: TeamFiltration Returns To Exploit Forgotten Service Accounts
Proofpoint identified UNK_CondorFiltration, an active TeamFiltration campaign that targeted more than 5,700 Microsoft 365 accounts across 28 tenants in Latin America, with a strong focus on Chilean organizations. All seven successful compromises were dormant service accounts with default or predictable passwords and no MFA, and at least one case showed follow-on...
www.hendryadrian.com
September 23, 2026 at 3:45 AM
TeamFiltrationキャンペーンが、デフォルトパスワードでMicrosoft 365アカウント7件を侵害。チリの小売・金融機関が標的。
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
TeamFiltration targeted over 5,700 Microsoft 365 accounts across 28 tenants, compromising seven service accounts with default passwords.
thehackernews.com
September 24, 2026 at 11:36 AM
TeamFiltration is back: forgotten M365 service accounts with no MFA are the easiest way in. https://intel.threadlinqs.com/threat/TL-2026-2616 #ThreatIntel #TeamFiltration #FireProx #Spraying
September 22, 2026 at 4:40 PM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Leer Más / Read More...
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Haz clic para acceder al contenido completo.
thehackernews.com
September 24, 2026 at 12:07 PM
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 t…
#hackernews #microsoft #news
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –
thehackernews.com
September 25, 2026 at 4:15 AM
@proofpoint.com
Password spraying compromised 7 unmanaged M365 service accounts lacking MFA.
-
IOCs: 3[.]101[.]0[.]0/16, 18[.]144[.]76[.]0/24, 149[.]88[.]104[.]19
-
#IdentitySecurity #TeamFiltration #ThreatIntel
TeamFiltration Sprays Chilean Service Accounts
www.proofpoint.com
September 23, 2026 at 4:08 AM
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 25, 2026 at 6:04 AM
Within 90 seconds of compromise, a threat actor triggered multiple post-access sequences. Our threat researchers believe this activity was AI-enabled.

Our new blog examines this active TeamFiltration campaign, tracked as UNK_CondorFiltration. www.proofpoint.com/us/blog/thre...
September 22, 2026 at 4:46 PM
TeamFiltration Hackers Breach Microsoft 365 Accounts by Targeting Forgotten Service Passwords sentinelcores.org/news/teamfil...
TeamFiltration Hackers Breach Microsoft 365 Accounts by Targeting Forgotten Service Passwords — SentinelCores
Proofpoint disclosed an active campaign, tracked as UNK_CondorFiltration, that fired over 32,000 login attempts at more than 5,700 Microsoft 365 accounts across 28 tenants using the open-source TeamFi...
sentinelcores.org
September 25, 2026 at 2:55 AM
I think I may know a guy…
https://t.co/DjCvykUb46

— from @rootsecdev (https://x.com/rootsecdev/status/2103087560025428309)
TeamFiltration Compromises Seven Microsoft 365 Accounts Using Default Passwords
t.co
September 24, 2026 at 12:47 PM
Hackers have been using the TeamFiltration pentesting framework to target more than 80,000 Microsoft Entra ID accounts at hundreds of organizations worldwide.
Password-spraying attacks target 80,000 Microsoft Entra ID accounts
Hackers have been using the TeamFiltration pentesting framework to target more than 80,000 Microsoft Entra ID accounts at hundreds of organizations worldwide.
www.bleepingcomputer.com
June 12, 2025 at 2:40 PM
Default passwords and no MFA led to Microsoft 365 service accounts being compromised—identity hygiene matters. #SecurityNews #IdentitySecurity #Microsoft365 #TeamFiltration #CloudSecurity https://thedailytechfeed.com/service-accounts-with-default-passwords-lead-to-microsoft-365-breaches/
September 24, 2026 at 6:45 AM
TeamFiltration UNK_CondorFiltration targeted 5,700+ Microsoft 365 accounts across 28 tenants using brute-force from 1,487 AWS EC2 IPs, compromising unmanaged service accounts lacking MFA.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 24, 2026 at 8:36 AM
TeamFiltration UNK_CondorFiltration targeted 5,700+ Microsoft 365 accounts across 28 tenants using brute-force from 1,487 AWS EC2 IPs, compromising unmanaged service accounts lacking MFA.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 24, 2026 at 8:35 AM
TeamFiltration UNK_CondorFiltration targeted 5,700+ Microsoft 365 accounts across 28 tenants using brute-force from 1,487 AWS EC2 IPs, compromising unmanaged service accounts lacking MFA.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 24, 2026 at 8:35 AM
A new threat actor named UNK_SneakyStrike used TrustedSec's TeamFiltration tool to enumerate Entra ID accounts and launch password-spraying attacks against 80k+ Entra ID accounts

www.proofpoint.com/us/blog/thre...
Attackers Unleash TeamFiltration: Account Takeover Campaign (UNK_SneakyStrike) Leverages Popular Pentesting Tool | Proofpoint US
Key takeaways  Proofpoint threat researchers have recently uncovered an active account takeover (ATO) campaign, tracked as UNK_SneakyStrike, using the TeamFiltration pentesting
www.proofpoint.com
June 11, 2025 at 11:27 PM
Safari ride-style showcase of password spraying tools & techniques with an extra flair for Entra ID-- featuring OpenBullet, MSOLSpray, entraspray, TeamFiltration & hints of FireProx, OmniProx, etc to finally simply rotate IPs low and slow with Tor. Video: youtu.be/oWv50EF0juc
October 20, 2025 at 1:01 PM
Over 80,000 Microsoft Entra ID user accounts have been compromised through a large-scale ATO campaign named UNK_SneakyStrike. This operation exploited TeamFiltration, an open-source penetration testing tool.

Via @thehackernews.bsky.social

#hacking #cybersecurity
Over 80,000 Microsoft Entra ID Accounts Targeted Using Open-Source TeamFiltration Tool
A new ATO campaign using TeamFiltration breached 80,000+ Microsoft Entra ID accounts via password spraying, impacting hundreds of cloud tenants
thehackernews.com
June 12, 2025 at 1:58 PM