Full Report
Even if employee accounts are locked down, forgotten and lost service accounts can undo an organization's entire M365 environment.
Analysis Summary
# Incident Report: M365 Data Theft via "Ghost" Service Accounts
## Executive Summary
A threat actor targeted Chilean organizations by exploiting overlooked non-human service accounts within Microsoft 365 environments. Despite successful defenses on employee-facing accounts, the attackers utilized basic credential spraying to compromise "ghost" service accounts with excessive permissions. This allowed the actors to bypass standard identity protections and exfiltrate sensitive enterprise data.
## Incident Details
- **Discovery Date:** Reported September 24, 2026
- **Incident Date:** Circa 2026
- **Affected Organization:** Multiple Chilean organizations (Unnamed)
- **Sector:** Various
- **Geography:** Chile
## Timeline of Events
### Initial Access
- **Date/Time:** 2026
- **Vector:** Credential Spraying
- **Details:** The threat actor targeted non-human identities (shared functional accounts, application accounts, and automated process accounts) using an open-source toolkit.
### Lateral Movement
- **Details:** Attackers leveraged the excessive permissions inherent in these "ghost" service accounts to navigate the M365 environment, bypassing restrictions that were strictly applied to human users.
### Data Exfiltration/Impact
- **Details:** Successful access to sensitive enterprise data stored within M365 services (likely SharePoint, OneDrive, and Outlook/Exchange) for the purpose of exfiltration.
### Detection & Response
- **How it was discovered:** Research unveiled by Proofpoint threat researchers at the Proofpoint Protect 2026 conference.
- **Response actions taken:** Discovery and public disclosure of the specific threat actor's methodology to alert regional organizations.
## Attack Methodology
- **Initial Access:** Credential Spraying against non-human accounts.
- **Persistence:** Utilization of valid, yet forgotten, service account credentials.
- **Privilege Escalation:** Exploitation of "excessive permissions" granted to automated accounts that were never audited or revoked.
- **Defense Evasion:** Targeting accounts that often lack Multi-Factor Authentication (MFA) or are excluded from standard identity monitoring policies.
- **Credential Access:** Basic spraying using the **TeamFiltration** OSS toolkit.
- **Discovery:** Identifying non-human/shared functional identities within the target M365 tenant.
- **Lateral Movement:** Cloud-based movement via M365 integrated services.
- **Collection:** Gathering sensitive enterprise documents and communications.
- **Exfiltration:** Standard cloud-based data exfiltration.
- **Impact:** Unauthorized data access and theft.
## Impact Assessment
- **Financial:** Not disclosed; costs associated with data loss and incident response.
- **Data Breach:** Exfiltration of sensitive enterprise-wide data.
- **Operational:** Potential disruption if service accounts were modified or deleted; ongoing risk if accounts remain unmanaged.
- **Reputational:** Risk to organizations in the Chilean region regarding data sovereignty and security posture.
## Indicators of Compromise
- **Network indicators:** Traffic associated with the **TeamFiltration** toolkit (defanged: hxxps[://]github[.]com/fl4l/TeamFiltration).
- **Behavioral indicators:** Failed login attempts across multiple accounts (spraying), followed by a successful login from an unusual IP/Geolocation on a service account; high-volume data access by a non-human identity.
## Response Actions
- **Containment:** Locking down identified compromised service accounts.
- **Eradication:** Password resets for all non-human and shared identities.
- **Recovery:** Auditing M365 logs to determine the extent of data accessed.
## Lessons Learned
- **The "Human" Bias:** Organizations often focus security efforts (like MFA and conditional access) solely on employee accounts while neglecting service accounts.
- **Account Governance:** "Ghost" accounts (forgotten relics) remain a high-value target because they often have default credentials and lacks active ownership.
- **Tooling Accessibility:** The use of Open Source Software (OSS) toolkits like TeamFiltration lowers the barrier to entry for effective cloud attacks.
## Recommendations
- **Identity Governance:** Implement a strict lifecycle management process for all non-human identities (creation to decommissioning).
- **Least Privilege:** Conduct regular audits of service account permissions to ensure they only have access to necessary data.
- **MFA for Service Accounts:** Where possible, use hardware tokens or conditional access policies to secure shared accounts.
- **Monitoring:** Set up specific alerts for sign-in activity involving service accounts from unexpected locations or at unusual times.
- **Secret Management:** Move away from static passwords for application accounts in favor of Managed Identities or Certificate-based authentication in M365.