← All posts

The Accounts Nobody Owns: How Seven Forgotten Logins Opened the Door

Attackers tried more than 5,700 accounts across 28 Microsoft 365 environments. They got into seven. Six of those fell within seven minutes.

The seven weren't executives, administrators, or anyone with a title. They were what Proofpoint's researchers called "forgotten, non-human identities carrying default or unrotated passwords and no MFA." In plain English: shared and automated logins that IT set up years ago, gave a default password, and never looked at again. Nobody owned them. Nobody was watching them.

What happened

Proofpoint tracked the campaign, which it calls UNK_CondorFiltration, from late July to mid-August 2026 and published its findings in September. The attackers used TeamFiltration, a legitimate security-testing framework that criminals can also use. The campaign ran from about 1,487 cloud-hosted IP addresses and focused almost entirely on organizations in Chile, including retail and financial institutions.

The method was not sophisticated. The attackers guessed default and predictable passwords against thousands of accounts and waited for a hit. The hits were all unmanaged service or functional accounts, the kind used by scanners, shared mailboxes, and applications rather than people. None of them had multi-factor authentication (MFA), the second step, such as a phone prompt, that stops a stolen password from being enough.

Once inside, the attacker moved quickly. Proofpoint observed access to the Azure portal and SharePoint within about 90 seconds of one compromise, along with an attempt to reach a corporate VPN. Other reporting says the attackers also reached OneDrive and Teams.

Why this belongs in the boardroom

It's tempting to file this under "technical hygiene." That's the mistake. This story is a clean example of the thesis behind Cyber Risk Is Business Risk: the gap between what leadership believes is protected and what is actually protected is where breaches live.

It's a compliance-versus-security problem. An organization can have an MFA policy, a signed-off access-control standard, and a clean audit, and still have dozens of accounts the policy never reached. Audits sample what's on the list. Attackers test what's not on the list. If your assurance comes from a checklist, ask whether the checklist includes accounts that aren't people.

It's a Three Questions problem. The framework asks what we're protecting, how we would know if it failed, and what we'd do next. For most boards, the answer to the first question quietly assumes "our employees' accounts." This campaign shows that non-human identities (service accounts, automation, integrations) are part of the answer, and they're the part least likely to have an owner. If no one owns an account, no one will notice when it behaves strangely.

It's a personal-accountability problem. When a regulator, insurer, or plaintiff asks what reasonable steps were taken, "we didn't know those accounts existed" is not a comforting answer. Directors are expected to ask informed questions about material risks. Asking about unowned identities is an informed question that costs nothing.

It will get worse with AI. As companies roll out AI assistants and automated agents, each one tends to arrive with its own service credentials. A 2026 industry survey reported by MSSP Alert found 77% of organizations had experienced Microsoft 365 governance incidents and that Copilot adoption had doubled to 56%. Every new automated tool is a potential new orphan account unless someone is assigned to track it. (These are survey findings, not measured outcomes, so treat them as direction, not precision.)

The budget conversation

Fixing this is among the cheapest security work there is. It doesn't require a new product. It requires an inventory, an owner for every account, rotated passwords, and MFA or equivalent protection wherever it can be applied. The expensive version is the one where you discover the problem after a breach.

This is the budget conversation I describe in the book: boards often fund the visible and the new, while the unglamorous basics go unfunded because they don't make a good slide. A one-time cleanup of unowned accounts is exactly that kind of basic.

What to ask your CISO this week

  1. How many non-human accounts do we have, and who owns each one? If the answer is "we're not sure," that's the finding. Ask for a date by which there will be a number.
  2. Which of them have default or never-rotated passwords? The attackers in this campaign didn't need a clever exploit. They needed a password nobody had changed.
  3. Which are exempt from MFA, and why? Exemptions are sometimes legitimate, such as an old system that can't support it. Each one should be written down, approved by a named person, and reviewed. Ask for the exemption list.
  4. Would we notice if one of them were used from a country we've never operated in? Monitoring unusual sign-ins on service accounts is a basic control that's often missing precisely because no one thought they needed it.
  5. Who is responsible when we add an AI tool or integration? Every new automation should come with an owner and an expiry review date.

The takeaway

Seven accounts out of more than 5,700 is a small success rate, and attackers don't mind. They only need one. The question for a board isn't whether an attacker will try your logins. It's whether the ones they find will be accounts that someone is responsible for.