Forgotten Microsoft 365 accounts expose emails, chats and files
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 25th, 2026.
Attackers compromised seven forgotten functional and service accounts at a major Chilean retailer after failing to breach any employee accounts. The broader campaign tested more than five thousand seven hundred accounts across 28 Microsoft 365 tenants using credential spraying and an open-source toolkit. Six of the seven successful compromises reportedly happened within seven minutes, pointing to weak or default credentials and missing multifactor authentication.
The attackers then used those accounts to extract emails, Teams conversations and OneDrive files. At least one account also reached Microsoft 365 management, Azure and SharePoint services. Nonhuman accounts can keep broad access long after their original business purpose has disappeared, especially when nobody clearly owns them. Every service identity should have a named owner, an expiration policy and regular access reviews. Defenders should inventory unusual account names, disable abandoned identities, and enforce strong authentication wherever the platform supports it. Protecting employee accounts isn’t enough when forgotten business identities remain open. Audit every Microsoft 365 service account now and remove or secure any identity without a current owner.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.