TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Summary
The TeamFiltration campaign, codenamed UNK_CondorFiltration, has compromised over 5,700 accounts across 28 Microsoft 365 tenants, with a particular focus on Chilean retail and financial institutions. The campaign originated from numerous AWS EC2 IP addresses and exploited default passwords to gain access to accounts.
IFF Assessment
This campaign represents a significant compromise of multiple accounts within business tenants, indicating a successful attack against organizations.
Defender Context
This campaign highlights the persistent threat of phishing and credential stuffing, particularly when default or weak passwords are used. Defenders should enforce strong password policies, implement multi-factor authentication, and continuously monitor for unusual login activity and compromised accounts, especially within targeted sectors like finance.