MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-24 · via The Hacker News

Microsoft 365 Accounts Breached in Widespread Default-Password Attack

Image via The Hacker News
Image via The Hacker News

Proofpoint researchers disclosed an active campaign called UNK_CondorFiltration that targeted over 5,700 accounts across 28 Microsoft 365 tenants. The operation focused on Chilean retail and financial institutions, originating from 1,487 unique AWS EC2 IP addresses. Seven accounts were compromised.

Expanded Detail

The disclosed campaign, tracked as UNK_CondorFiltration, leveraged default passwords to breach Microsoft 365 environments, affecting more than 5,700 user accounts spread across 28 tenants. Attackers routed their activity through a large pool of nearly 1,500 Amazon Web Services EC2 IP addresses, complicating detection and attribution. The primary targets were retail and financial organizations in Chile, with seven accounts ultimately confirmed as compromised.

This incident highlights how basic credential hygiene remains a critical vulnerability even in cloud-based enterprise systems. Default or weak passwords, often overlooked in large deployments, can provide an easy entry point for automated attacks. The use of cloud infrastructure for command and control further underscores the challenge of distinguishing legitimate traffic from malicious activity in modern networks.

Context

This breach could affect not only the targeted Chilean firms but also their customers, whose financial or personal data may be at risk. Widespread default-password attacks may pressure organizations to enforce stronger authentication policies, such as multi-factor verification. However, the relatively low number of confirmed compromises suggests that many accounts were protected, though the potential for lateral movement or future exploitation remains a concern for the broader business community.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords.” Browse more stories.