Proofpoint detailed an active TeamFiltration credential-spraying campaign it calls UNK_CondorFiltration that targeted more than 5,700 accounts across 28 Microsoft 365 tenants from 1,487 unique AWS EC2 source addresses, in three waves between late July and August 2026. The first two waves, on 21–24 July and 26–28 July, were aimed at major Chilean banks, peaking at about 1,520 targeted accounts on 27 July; the third, 13–16 August, hit a major Chilean retailer, peaking near 1,560 accounts and producing the campaign's only compromises. All seven compromised accounts were unmanaged functional or service accounts carrying default or unrotated passwords and no MFA — not a single employee account was breached. The affected retailer absorbed 78.3% of all observed authentication events. Defenders should inventory by exception: usernames that do not follow the organisation's naming convention are the fastest way to surface non-human identities with standing access.
| Attribute | Detail |
|---|---|
| Sector | Financial Services |
| Date | 2026-09-25 |
| Source | The Hacker News |
| Reliability | Tier 2 |