A TeamFiltration campaign hit over 5,700 Microsoft 365 accounts across 28 tenants, compromising 7 using default passwords. Here's what you need to know.
### A Wake-Up Call from the TeamFiltration Campaign
Cybersecurity researchers have just pulled back the curtain on a TeamFiltration campaign that's been quietly making the rounds. It's called UNK_CondorFiltration, and it's already hit over 5,700 accounts across 28 Microsoft 365 tenants. That's not a small number—it's a full-scale assault on cloud identities.
The campaign, according to Proofpoint, has been laser-focused on Chilean retail and financial institutions. But don't let the geography fool you. The techniques used here are universal, and they could just as easily be aimed at your organization next.
What's really striking is where the attacks came from: 1,487 unique AWS EC2 source IP addresses. That's a massive infrastructure, likely rented or compromised, giving the attackers plenty of places to hide.
### The Password Problem That Won't Go Away
So how did they get in? The short answer: default passwords. Yes, in 2025, we're still seeing breaches caused by credentials that should have been changed on day one.
It's the digital equivalent of leaving your front door key under the welcome mat. Attackers know people get lazy. They count on it.
Here's the kicker: the campaign only compromised 7 accounts. That might sound small, but each one is a potential doorway into an entire organization. One compromised account can lead to data theft, financial fraud, or a full-blown ransomware attack.
### Why Microsoft 365 Is a Prime Target
Microsoft 365 is the backbone of countless businesses. It holds emails, documents, chats—basically your company's entire digital life. When attackers get a foothold there, they can move laterally, escalate privileges, and cause chaos.
And because it's cloud-based, traditional security perimeters don't always catch them. You need visibility into every login, every device, every session.
> "The campaign compromised 7 accounts – but the real damage is what happens after the initial breach. Attackers often linger for weeks, quietly exfiltrating data."
### How to Protect Your Organization
Prevention starts with the basics, but you have to actually do them:
- **Change default passwords immediately.** No exceptions. If a device or service comes with a default, change it before it touches your network.
- **Enable multi-factor authentication (MFA).** It's not foolproof, but it stops the vast majority of credential-based attacks.
- **Monitor for unusual activity.** Tools like Microsoft Defender for Cloud Apps can flag impossible travel, mass downloads, or suspicious inbox rules.
- **Limit privileged accounts.** Not everyone needs admin rights. Least privilege is your friend.
- **Educate your team.** Phishing and social engineering often go hand-in-hand with these campaigns.
### The Bigger Picture: Antidetect Browsers and Attack Vectors
While this campaign used default passwords, attackers are constantly evolving. One trend we're watching closely is the use of antidetect browsers to bypass security controls. These tools let cybercriminals manage multiple fake identities, evade fingerprinting, and automate attacks at scale.
For defenders, it means you can't rely solely on IP blocking or device fingerprinting. You need behavioral analytics and anomaly detection.
### What Comes Next
Proofpoint's report is a reminder that basic hygiene still matters. The attackers aren't always using zero-days; sometimes they're just trying the front door.
If you haven't audited your Microsoft 365 environment lately, now's the time. Check for stale accounts, enforce strong passwords, and turn on MFA. It's not glamorous, but it works.
And keep an eye on those AWS IPs—they might just be the next wave.