Act
active
TeamFiltration Sprays M365 Tenants via Default Passwords, 7 Accounts Compromised
- Engineer — Plan: TeamFiltration targets M365 tenants using default/weak credentials; audit your tenant for accounts lacking MFA and enforce Conditional Access policies requiring phishing-resistant auth before this campaign broadens its target geography.
- SOC/IR — Act: Active M365 credential-spray campaign is live and compromising accounts; hunt for TeamFiltration enumeration patterns in Azure AD sign-in logs and flag clusters of authentication attempts originating from AWS EC2 CIDR ranges with mixed failure/success ratios.
- Leader — Learn: Seven-account compromise across 28 tenants is low scale and currently regional (Chilean retail/finance), but the default-password attack path is a useful data point for board-level conversations about basic credential hygiene and MFA adoption metrics.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.