Skip to content
Ghost Service Accounts Enable M365 Data Theft in Chile

Ghost Service Accounts Enable M365 Data Theft in Chile

Darkreading • September 24, 2026

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.

Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization's entire M365 environment.

Hackers are leveraging overlooked machine accounts in Microsoft 365 (M365) to steal enterprise data from organizations in Chile.

Within any organization's M365 environment, there are accounts that belong to humans, sure, but also shared functional identities and accounts for applications and automated processes. Individuals are responsible for their own identities, but who keeps track of, maintains, and secures those nonhuman ones ? Without due diligence, those types can fall out of focus and become forgotten relics with default credentials and excessive permissions.

At Proofpoint Protect 2026 in San Diego, Calif., researchers at Proofpoint unveiled an as-yet-unknown threat actor trying to break into Chilean organizations' M365 environments . Using an open source (OSS) toolkit and basic credential spraying, the actor didn't manage to break into a single employee account belonging to any of their targets. Instead, nonhuman accounts became their key to getting in, allowing them to gain access to a variety of sensitive data worth exfiltrating.

Related: China's FamousSparrow APT Spies on US Politics in Latin America

M365 Compromise in Chile

Using the "TeamFiltration" tactic is one of the easiest, laziest ways to hack an organization's M365 environment. Developed half a decade ago and debuted to the public as part of the fantastically titled DEF CON 30 presentation, "Taking a Dump in the Cloud," TeamFiltration is an all-in-one, OSS M365 hacking kit. Ethical and nonethical hackers alike can point it at a M365 tenant, enumerate the accounts it contains, and brute-force them, all while rotating infrastructure to avoid IP blocking. Then the tool can facilitate broad data exfiltration and backdooring across connected Microsoft applications.

Beginning on July 21, a threat actor that Proofpoint currently tracks as UNK_CondorFiltration began a TeamFiltration campaign. At first, it probed hundreds of M365 accounts associated with two major banking institutions in Chile. A week later, it probed thousands at a third financial institution in the same country. None of this appears to have amounted to much.

After a quiet couple of weeks, in mid-August, the threat actor came back with a third wave of TeamFiltration attacks. This time, it aimed all of its cannons at a single target: a major Chilean retailer. And this time, it succeeded in compromising seven corporate accounts.

The breakthrough wasn't some new tool or tactic. In a campaign spanning more than 5,700 accounts across 28 different M365 tenants, UNK_CondorFiltration still hadn't breached a single employee account. However, this time, it had identified seven functional and service accounts that the retailer seemed to have forgotten , or perhaps never knew existed.

Related: Cyber Op Targets South Korean Media & Automotive Sectors

Not one of these accounts had any active user history. Nobody ever logged in to them or used them to perform an action. They'd been created for business functions — such as managing tickets or approving vendor payments — and then, apparently, forgotten. They likely contained default or even shared credentials, with no multifactor authentication (MFA) protection, as the threat actor compromised six of them in seven minutes.

With initial access secured, the attacker used TeamFiltration's auto-exfiltration function to pull emails, chat conversations, and files from Outlook, Teams, and OneDrive . In at least one case, they went further: probing the company's virtual private network (VPN), accessing both its M365 management portal and the Azure portal from which it manages its cloud services, and browsing its SharePoint files.

How Nonhuman Accounts Become Liabilities

UNK_CondorFiltration's victim is hardly unique, says Yaniv Miron, director of threat research for Proofpoint. At any given organization, he explains, "a lot of service accounts are being created for different purposes. Then when that purpose is no longer needed, nobody's making sure that user is locked out or disabled." Worse, he adds, "Sometimes accounts are being created not in any official way, by teams that don't officially document it." As a result, the exact kinds of employees that could otherwise secure these rogue accounts might not even know they exist.

Related: Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

The best way to prevent this behavior, he argues, is to tether every cloud account to a human employee, even if the account performs only automated functions. That way, at least, there's an individual responsible for it. On top of that, organizations can assign expiration dates to accounts to make sure that those unaccounted for at least don't live very long.

Before an organization protects its future accounts, though, it must inventory whatever insecure accounts it may already be housing. To root out those that already pose a threat, Miron advises that admins go hunting for usernames that don't fit an organization's typical naming convention.

"An IT guy or a SOC team member could just write a script that runs through all users in 365 and figures out any account name that is not built in that specific way," he says. "Probably, all of those users that have random names [are worth] looking into, to see what their purpose is."

Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.

He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.

He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.

Want more Dark Reading stories in your Google results?

The State of Cloud Security: The Latest Challenges

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Essential News & Insights from Black Hat USA 2025

Effective Alert Triage: Reducing Noise and Finding Real Threats

Effective Alert Triage: Reducing Noise and Finding Real Threats

Cybersecurity Outlook 2027

Cybersecurity Outlook 2027

Threat Exposure Analytics: Measuring and Communicating Security Risk

Threat Exposure Analytics: Measuring and Communicating Security Risk

Benchmark Scores Are a False Flag

Benchmark Scores Are a False Flag

Building an Effective Red Team: Beyond Penetration Testing

Building an Effective Red Team: Beyond Penetration Testing

Operation DoppelBrand: Weaponizing Fortune 500 Brands

CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks

Deja Vu: Salesforce Customers Hacked Again, Via Gainsight

Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business

Extracted Entities