"5,700 Microsoft 365 accounts hit by one automated tool"
Key takeaways
- UNK_CondorFiltration has hit over 5,700 Microsoft 365 accounts across 28 tenants
- The campaign uses TeamFiltration, a free open-source penetration testing tool
- Attack relies on credential stuffing and session token theft, not novel exploits
- Conditional access and MFA app policies significantly reduce exposure
Free tools, thousands of accounts
You don't need a nation-state budget to compromise thousands of corporate accounts. You need a free tool, a list of leaked passwords, and organisations that haven't turned on the security settings sitting right there in their admin console.
That's the story behind UNK_CondorFiltration, a campaign security researchers have been tracking that has compromised more than 5,700 Microsoft 365 accounts across 28 separate organisations. The tool doing the damage is TeamFiltration, an open-source framework originally built for legitimate penetration testing, now repurposed wholesale for account takeover at scale.
How it works
TeamFiltration automates the unglamorous but effective parts of account compromise: spraying stolen or guessed credentials against Microsoft 365 login endpoints, then, once a password lands, hijacking the session tokens that keep a user logged in without needing to re-enter a password. That second part is what makes it dangerous even against accounts with multi-factor authentication, if the MFA setup doesn't also protect session tokens themselves.
Because the tool automates the entire pipeline, a single operator can run it against many organisations in parallel rather than manually targeting one company at a time. That's the real shift here: this isn't a sophisticated custom-built exploit, it's mass-market automation doing damage because basic account hygiene isn't in place at enough organisations.
Why 28 tenants, one campaign
Microsoft 365 is the backbone of email, file storage and collaboration for a huge share of small and mid-sized businesses. It's also a single point of failure: an attacker inside a Microsoft 365 account often has a launchpad into email-based fraud, further phishing against a company's contacts, and access to shared files and internal communications.
The 28 affected organisations span a range of sectors, and researchers note the campaign appears opportunistic rather than targeted at any one industry. That's consistent with a credential-stuffing operation: it goes after whichever accounts have reused or leaked passwords, not a specific target list.
What actually stops this
The fixes here are unglamorous and already exist inside Microsoft 365 admin settings. Conditional access policies that block sign-ins from unfamiliar locations or unmanaged devices cut off a large share of this kind of attack before it starts. Requiring MFA through an authenticator app rather than SMS closes off the weakest form of two-factor. And session lifetime policies that force periodic re-authentication limit how long a stolen token stays useful even if one does get through.
If your business runs on Microsoft 365, this is worth an afternoon this week: check the sign-in logs in the admin centre for logins from unexpected countries or IP ranges, and if conditional access isn't already turned on, turn it on.