Cybersecurity Threatens Chile’s Financial Sector: UNK_CondorFiltration Campaign Targets 5,700 Accounts in Microsoft 365
By Ravie Lakshmanan | September 24, 2026
Cybersecurity researchers have recently uncovered an active campaign by the malicious group TeamFiltration, codenamed UNK_CondorFiltration, which has decisively affected financial and retail institutions in Chile. The campaign is alarming and multifaceted, targeting over 5,700 accounts spanning across 28 Microsoft 365 tenants. The implications of such breaches underline the vulnerabilities within organizational security structures, particularly concerning service accounts that are often overlooked.
According to the findings disclosed by Proofpoint, this campaign predominantly focused on sectors critical to the Chilean economy, notably retail and financial institutions. The origin of the attacks can be traced back to a staggering 1,487 unique AWS EC2 source IP addresses, showcasing the extensive reach and determined efforts of the cybercriminals behind this initiative.
The primary observations indicate that seven accounts, which were compromised during the operation, were all unmanaged functional or service accounts—rather than individual employee accounts. This highlights a significant exposure gap related to unmonitored digital identities that often carry default or unrotated passwords and lack multi-factor authentication (MFA) protection. Proofpoint provided this insight through an official statement, identifying a pressing need for organizations to reevaluate their security protocols concerning these types of accounts.
The UNK_CondorFiltration campaign unfolded across three distinct waves from late July to the following August, with an unnamed Chilean retailer bearing the brunt of the attacks, accounting for an astonishing 78.3% of all observed authentication events.
-
First Wave (July 21-24): This initial phase targeted approximately 100 to 120 unique accounts daily at two major Chilean banks.
-
Second Wave (July 26-28): Here, the actors escalated their efforts, with an astonishing peak of about 1,520 accounts affected on July 27, primarily directed against another significant financial institution.
- Third Wave (August 13-16): This final wave saw the attackers peak at approximately 1,560 accounts on August 15, once again focusing their efforts on a major retail player.
Evidence from the research indicates that the threat actors likely employed a brute-force strategy, spraying accounts with default passwords, many of which had been provisioned by IT teams and had not undergone any rotation. Intriguingly, their focus was largely on dormant service accounts, a demographic often ignored by companies due to a false sense of security surrounding less frequently monitored accounts.
Proofpoint emphasized that the compromised service accounts, designed to facilitate business operations, were left unmonitored and retained their original credentials. Disturbingly, six out of the seven compromised accounts were breached within a mere seven minutes. This quick access is suggestive of a shared or default password scenario rather than a highly targeted credential stuffing approach.
The UNK_CondorFiltration campaign is notable for the utilization of TeamFiltration, a legitimate cross-platform offensive framework developed for enumerating, spraying, exfiltrating, and backdooring Entra ID accounts. This framework enables operators to validate email accounts, test common or targeted passwords against enumerated accounts, collect sensitive data, and gain covert entry to OneDrive.
Once access was obtained, the affected accounts often served as a gateway for the attackers into vital Microsoft services, such as Office, OneDrive, and Teams—potentially indicative of an intent to harvest and exfiltrate sensitive data. Nevertheless, it is crucial to note that mere sign-in events do not serve as conclusive evidence of data exfiltration.
Alarmingly, less than two minutes following successful compromises, the attackers were observed pivoting to a German VPN node to explore additional vulnerabilities in the corporate VPN, access the Azure Portal, browse SharePoint Online, and initiate token requests through the Microsoft Graph API.
This incident is not the first instance of TeamFiltration being leveraged for malicious activities. In June 2025, Proofpoint identified another threat cluster named UNK_SneakyStrike, which threatened over 80,000 user accounts across various organizations using the same open-source penetration testing framework.
The UNK_CondorFiltration campaign serves as a significant reminder about the vulnerabilities prevalent in enterprise identity perimeters. Proofpoint stresses that one of the weakest links often lies not in phishing attempts against employees or zero-day exploits, but rather in what are known as "forgotten accounts." These service accounts, created for convenience and neglected over time, form a structurally unprotected attack surface ripe for exploitation.
In light of these findings, organizations must prioritize a comprehensive review of their cybersecurity measures and ensure that all accounts, especially those categorized as service accounts, are regularly monitored and maintained to mitigate potential risks.
