TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
What Happened — Proofpoint researchers identified an active TeamFiltration operation (code‑named UNK_CondorFiltration) that targeted more than 5,700 accounts across 28 Microsoft 365 tenants. The campaign successfully hijacked seven accounts by exploiting unchanged default passwords, originating from 1,487 distinct AWS EC2 IP addresses and focusing on Chilean retail and financial institutions.
Why It Matters for Trust & Control Assurance
- Highlights a failure in credential‑management controls that a continuous‑control‑assurance program is designed to detect and remediate.
- Demonstrates the need for enforceable password policies, MFA, and real‑time login monitoring to produce defensible audit evidence.
- Directly maps to the Access Control objective in the Verisq Common Framework, which satisfies multiple frameworks (e.g., NIST CSF, ISO 27001).
Who Is Affected — Financial services firms and retail organizations using Microsoft 365 in Chile (and any tenant with similar password practices).
Recommended Actions
- Enforce MFA for all Microsoft 365 users.
- Conduct an immediate audit to identify and disable default or weak passwords.
- Deploy continuous login‑anomaly detection and retain logs as audit‑ready evidence.
Source: The Hacker News
Technical Notes
- Attack vector: exploitation of default passwords (misconfiguration).
- Source infrastructure: 1,487 unique AWS EC2 IPs.
- No public disclosure of data exfiltration; impact is potential exposure through compromised accounts.
Source: The Hacker News