Hackers are exploiting unsecured machine accounts in Microsoft 365 (M365) to steal sensitive data from Chilean enterprises This article explores 365 identifies accounts. . At Proofpoint Protect 2026 in San Diego, Calif., researchers at Proofpoint disclosed an unknown threat actor attempting to breach Chilean organizations' Microsoft 365 environments.
Using an open source toolkit and basic credential spraying, the actor failed to compromise any employee accounts belonging to their targets. Instead, non-human accounts were utilized, enabling them to gain access to a wide array of sensitive data, allowing for its exfiltration. This tactic was developed over five years ago and was first introduced at DEF CON 30 as part of the "Taking a Dump in the Cloud" presentation. The game-changing development wasn't a new gadget or strategy.
Related: Cyber Op Targets South Korean Media & Automotive Sectors Proofpoint's Yaniv Miron highlights that many service accounts are created for various purposes within organizations. To identify those that pose a threat, Miron suggests that administrators search for usernames that don't adhere to the organization's standard naming conventions. An IT professional or a SOC team member could create a script that scans all users in Microsoft 365 and identifies any accounts that do not adhere to a specific format.
This script would likely reveal that many of these users with random names are worth investigating to understand their intended purpose.











