decrypted · 5 october 2026 · vulnerabilities and patching · uk policy and law · ai and llm security

Seven forgotten Microsoft 365 accounts, and the default passwords that opened them

Most security stories this week are about clever exploits. This one is about a password nobody remembered setting. In research published in late September, Proofpoint described a campaign that tried default passwords against 5,714 Microsoft 365 accounts across 28 organisations and got into seven. None of the seven belonged to a person. Each was a service or functional account, created for convenience, never rotated and never protected by multi-factor authentication. The targets were mostly Chilean, but the weakness is not national. Any UK organisation with a few years of Microsoft 365 behind it probably owns a few accounts like these.

How the campaign worked

Proofpoint tracks the activity as UNK_CondorFiltration. It was built on TeamFiltration, an open penetration testing framework. The operator ran three waves between 21 July and 16 August, generating 32,825 authentication events from 1,487 Amazon cloud addresses. Each address makes only a few guesses, so lockout rules and simple rate limits never see a pattern.

Picture a thief walking along a street of offices, trying the same spare key in every back door. He does not need to know anyone's name. He needs one door where someone left the factory lock fitted. Six of the seven successful sign-ins landed within seven minutes, which suggests the accounts shared the same default password.

What the attacker did next

Within about 90 seconds of logging in, the operator switched to a German VPN node. From there they reached Azure Portal, SharePoint Online and the victim's corporate VPN, and tried to obtain Microsoft Graph tokens. The Hacker News, reporting the same research, lists Office, OneDrive and Teams among the services touched.

What the defender sees

Very little, and that is the point. The sign-in succeeds with the correct password. The account has no owner to notice odd behaviour and no user to complain. Proofpoint noted that none of the seven accounts had any prior legitimate sessions, which is itself the best detection available: an account that has never signed in, suddenly signing in from a cloud address, is rare enough to alert on. The tool also leaves a fingerprint, a hardcoded Teams user agent string, Teams/1.3.00.30866, which modern clients no longer send.

The Secure by Design lesson

The Hacker News quotes Proofpoint's conclusion: "The forgotten account. Service accounts provisioned for convenience and never revisited are a structurally unprotected attack surface."

The design decision that would have prevented this is simple to state. A non-human identity should never authenticate with a human-style password. Where a task needs to log in, use a managed identity or a certificate, and where a password is unavoidable, restrict where it can be used from and require a second factor or a conditional access rule.

The cost of applying this is modest and mostly awkward. It is an inventory of every account that has never had a person attached, a hunt for whoever owns the old scanner-to-email setup, and the nerve to switch off what nobody can explain.

This is opinion, not advice, but the control point is clear. You cannot govern an account you do not know you own, and attackers are now spending cloud money to find the ones you have forgotten.

Also this week

Policy: the Lords bill that would widen NIS. The Cyber Security and Resilience (Network and Information Systems) Bill finished Lords committee stage on 7 September, and report stage is scheduled for Monday 26 October, according to the parliamentary tracker. The bill extends the NIS regime to more types of organisation, tightens incident reporting, and creates "critical supplier" designations, which matters to anyone selling managed services into essential sectors. Royal Assent has not happened, so nothing here is law yet. The sensible move for suppliers is to ask now what a designation would demand of them, rather than after the amendments settle. Today's lead is a fair example of what regulators will expect the basics to cover: if a supplier's tenant holds forgotten accounts, its customers inherit the risk.

AI security: a shared instruction became code execution. CodeAnt's researchers published a write-up on 2 October of a stored prompt injection in Manus, an AI agent product. According to their account, text placed in a shared project's instruction field was loaded into every member's agent as trusted configuration, which let it run code in other users' sandboxes and, in their demonstration, take over a remote desktop. They reported it through Meta's bug bounty and say it was fixed on 16 September. This is the researchers' own account, and we have not seen a vendor statement. The design lesson is an old one: never let content written by one person reach another person's agent with the same trust as the system's own rules.

Sources

If forgotten accounts or supplier obligations are on your mind, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.