Threat Intelligence Brief
Curated summary with source attribution
Source: infostealers.com
Threat Risk: High
Victim: Fortune 500 Enterprises
Incident: Mass exfiltration of employee directory data from Azure Tenants.
Impact: Exposure of millions of employee records and highly privileged account mappings.
Attacker: TheHatman
Analysis: The threat actor ‘TheHatman’ is selling datasets extracted from Azure/Entra portals using compromised credentials. The leak is particularly dangerous because it includes global administrator lists and service account details. This level of visibility allows attackers to map organizational hierarchies and target high-value users for precision spear-phishing.
Recommendations: Enforce phishing-resistant MFA for all Azure/Entra portal access; Audit and rotate credentials for all Global Administrator and service accounts; Monitor for anomalous login patterns and session token theft
Source: InfoStealers / Hudson Rock
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source