# Ghost Service Accounts Enable M365 Data Theft in Chile
Forgotten and dormant service accounts in Microsoft 365 environments pose a direct path to enterprise data theft, according to security research from Chile. Attackers bypass traditional access controls by exploiting service accounts that organizations have lost track of, allowing unauthorized users to extract sensitive data even when employee accounts face strict lockdown policies.
The vulnerability stems from a common operational blind spot. Service accounts exist to enable automated processes, system integrations, and application functions. Unlike user accounts, they often operate without login credentials tied to specific individuals. When organizations retire applications, migrate systems, or restructure IT operations, these accounts frequently fall into administrative limbo. No one remembers they exist. No one maintains their credentials. They persist silently in the M365 tenant with standing permissions.
Attackers who gain access to these orphaned accounts inherit the permissions those accounts retained. In M365 environments, this translates to reading email, accessing SharePoint repositories, downloading OneDrive files, and exfiltrating Teams conversations. The attacker operates under a service account identity that standard monitoring often overlooks because these accounts typically generate baseline activity patterns that defenders expect and ignore.
The Chile-based research highlights a practical attack flow. An attacker gains initial access to the network through phishing, compromised credentials, or supplier access. Instead of immediately targeting active user accounts, the attacker enumerates M365 service accounts by querying Azure AD, examining application authentication logs, or reviewing integration configurations. Once a dormant account is identified, the attacker leverages its standing permissions to extract data methodically, sometimes over weeks or months without triggering alerts.
Organizations face three compounding problems. First, they lack inventory. Most companies cannot quickly list all service accounts in their M365 environments, let alone confirm which ones remain actively needed. Second, governance fails. Service accounts often escape rotation policies, conditional access rules, and credential management protocols. Third, detection gaps exist. Service accounts generate different activity patterns than users, and security teams rarely baseline or alert on unusual service account behavior.
The attack pattern carries heightened risk in environments where employee accounts face modern security controls. Multi-factor authentication, conditional access policies, and session controls now make direct user account compromise harder. Service accounts, by contrast, often authenticate without MFA or from fixed IP addresses that appear trusted.
Mitigation requires urgent inventory and deprovisioning work. Organizations should query Azure AD for all service accounts, document their purpose and permissions, and immediately disable any account no longer actively used. For retained accounts, enforce credential rotation, implement monitoring and alerting on data export activities, and restrict permissions to only what the account requires. Conditional access policies should apply to service accounts identically to user accounts, including MFA requirements where technically feasible.
The research serves as a reminder that access control strength depends entirely on knowing what accounts exist and maintaining continuous visibility into their use. A single forgotten service account can render enterprise-wide security policies ineffective. Security teams should treat service account discovery and governance as a standing operational priority, not a one-time audit task.
