# TeamFiltration Campaign Exploits Default Credentials to Breach Microsoft 365 Tenants

Attackers operating under the TeamFiltration campaign, tracked as UNK_CondorFiltration, have successfully compromised seven Microsoft 365 accounts by exploiting default or weak passwords. Proofpoint researchers disclosed the operation, which has cast a wide net across 28 separate Microsoft 365 tenants targeting Chilean retail and financial organizations.

The scope of reconnaissance extends far beyond the successful breaches. Attackers probed more than 5,700 accounts across the 28 targeted tenants, searching for vulnerable entry points. The campaign originated from 1,487 distinct AWS EC2 IP addresses, suggesting the threat actors leveraged cloud infrastructure to distribute their attack infrastructure and evade detection.

This campaign represents a fundamental security failure: organizations deploying Microsoft 365, often treated as inherently secure cloud infrastructure, left accounts accessible through default or trivial credentials. While only seven accounts were successfully compromised during the observed campaign window, the reconnaissance against 5,700+ accounts signals a methodical, large-scale operation searching for low-hanging fruit.

Microsoft 365 administrators face persistent pressure to balance user accessibility with security controls. Default passwords and weak credential policies remain widespread despite best practices that have existed for decades. The Chilean financial and retail sectors, targeted here, typically handle sensitive customer data and payment information. A successful compromise of legitimate administrative or user accounts grants attackers legitimate access to email, files, and potentially connected systems without triggering alerts that would flag suspicious login attempts from known threat actors.

The use of AWS EC2 instances amplifies the attack's scale. Threat actors can rotate through hundreds of ephemeral cloud instances, each with distinct IP addresses. This distributes attack traffic and complicates attribution and blocking efforts. Networks relying solely on IP-based blocking find themselves fighting a moving target. AWS IP addresses also carry less suspicion than obviously suspicious or obviously malicious ISP ranges, allowing more reconnaissance traffic to reach target systems.

The TeamFiltration framework itself specializes in exfiltrating Microsoft 365 data. The tool targets email, Teams messages, SharePoint files, and OneDrive contents. In the hands of cybercriminals or nation-state actors, access to a financial or retail company's Microsoft 365 tenant exposes trade secrets, customer records, payment processing details, and internal communications. For Chilean financial institutions specifically, regulatory violations and customer notification requirements trigger substantial financial penalties and reputational damage.

Organizations operating Microsoft 365 should treat default password mitigation as a baseline control, not an optional hardening measure. Conditional Access policies within Azure AD can enforce device compliance, geographic restrictions, and multi-factor authentication. Regular audits of active accounts and their permissions identify stale administrative accounts that retain unnecessary privileges. Password policies that enforce complexity and length, combined with passwordless authentication methods like Windows Hello for Business or FIDO2 tokens, eliminate entire classes of credential-based attacks.

The seven compromised accounts now belong to a known breach list. Organizations tracking breach notifications should monitor for employee credentials from this campaign appearing in subsequent attacks, insider threat activity, or data sales. Third parties relying on Chilean retail or financial firms for services face potential supply chain exposure if those organizations' data leaked.