Ghost Service Accounts Enable M365 Data Theft in Chile

A digital, artistic representation of the Chilean flag
Source: Gwengoat via Getty Images

Hackers are leveraging overlooked machine accounts in Microsoft 365 (M365) to steal enterprise data from organizations in Chile.

Within any organization's M365 environment, there are accounts that belong to humans, sure, but also shared functional identities and accounts for applications and automated processes. Individuals are responsible for their own identities, but who keeps track of, maintains, and secures those nonhuman ones? Without due diligence, those types can fall out of focus and become forgotten relics with default credentials and excessive permissions.

At Proofpoint Protect 2026 in San Diego, Calif., researchers at Proofpoint unveiled an as-yet-unknown threat actor trying to break into Chilean organizations' M365 environments. Using an open source (OSS) toolkit and basic credential spraying, the actor didn't manage to break into a single employee account belonging to any of their targets. Instead, nonhuman accounts became their key to getting in, allowing them to gain access to a variety of sensitive data worth exfiltrating.

M365 Compromise in Chile

Using the "TeamFiltration" tactic is one of the easiest, laziest ways to hack an organization's M365 environment. Developed half a decade ago and debuted to the public as part of the fantastically titled DEF CON 30 presentation, "Taking a Dump in the Cloud," TeamFiltration is an all-in-one, OSS M365 hacking kit. Ethical and nonethical hackers alike can point it at a M365 tenant, enumerate the accounts it contains, and brute-force them, all while rotating infrastructure to avoid IP blocking. Then the tool can facilitate broad data exfiltration and backdooring across connected Microsoft applications.

Beginning on July 21, a threat actor that Proofpoint currently tracks as UNK_CondorFiltration began a TeamFiltration campaign. At first, it probed hundreds of M365 accounts associated with two major banking institutions in Chile. A week later, it probed thousands at a third financial institution in the same country. None of this appears to have amounted to much.

After a quiet couple of weeks, in mid-August, the threat actor came back with a third wave of TeamFiltration attacks. This time, it aimed all of its cannons at a single target: a major Chilean retailer. And this time, it succeeded in compromising seven corporate accounts.

The breakthrough wasn't some new tool or tactic. In a campaign spanning more than 5,700 accounts across 28 different M365 tenants, UNK_CondorFiltration still hadn't breached a single employee account. However, this time, it had identified seven functional and service accounts that the retailer seemed to have forgotten about, or perhaps never knew existed.

Not one of these accounts had any active user history. Nobody ever logged in to them or used them to perform an action. They'd been created for business functions — such as managing tickets or approving vendor payments — and then, apparently, forgotten. They likely contained default or even shared credentials, with no multifactor authentication (MFA) protection, as the threat actor compromised six of them in seven minutes.

With initial access secured, the attacker used TeamFiltration's auto-exfiltration function to pull emails, chat conversations, and files from Outlook, Teams, and OneDrive. In at least one case, they went further: probing the company's virtual private network (VPN), accessing both its M365 management portal and the Azure portal from which it manages its cloud services, and browsing its SharePoint files.

How Nonhuman Accounts Become Liabilities

UNK_CondorFiltration's victim is hardly unique, says Yaniv Miron, director of threat research for Proofpoint. At any given organization, he explains, "a lot of service accounts are being created for different purposes. Then when that purpose is no longer needed, nobody's making sure that user is locked out or disabled." Worse, he adds, "Sometimes accounts are being created not in any official way, by teams that don't officially document it." As a result, the exact kinds of employees that could otherwise secure these rogue accounts might not even know they exist.

The best way to prevent this behavior, he argues, is to tether every cloud account to a human employee, even if the account performs only automated functions. That way, at least, there's an individual responsible for it. On top of that, organizations can assign expiration dates to accounts to make sure that those unaccounted for at least don't live very long.

Before an organization protects its future accounts, though, it must inventory whatever insecure accounts it may already be housing. To root out those that already pose a threat, Miron advises that admins go hunting for usernames that don't fit an organization's typical naming convention.

"An IT guy or a SOC team member could just write a script that runs through all users in 365 and figures out any account name that is not built in that specific way," he says. "Probably, all of those users that have random names [are worth] looking into, to see what their purpose is."

Dive deeper

Free tools to verify and analyze what this article covers:

source: DarkReading