Hacker claims massive employee data haul from major companies’ Azure accounts

August 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: computing.co.uk

Threat Risk: High
Victim: Global enterprises utilizing Microsoft Azure/Entra
Incident: Mass extraction of employee directory data from multiple corporate Azure tenants.
Impact: Exposure of millions of employee records, potentially enabling advanced social engineering and account takeover.
Attacker: TheHatman
Analysis: The attacker, known as ‘TheHatman,’ leveraged compromised credentials to export directory data from Microsoft Entra. The stolen information includes sensitive organizational hierarchies and privileged account identifiers, which could facilitate targeted spear-phishing or lateral movement. While some victims claim the data is public-facing, the scale of the export suggests a systemic failure in credential hygiene across multiple tenants.
Recommendations: Implement phishing-resistant MFA, such as FIDO2, to prevent credential harvesting.; Audit third-party application permissions within Microsoft Entra to ensure least-privilege access.; Review Global Administrator accounts and implement Just-In-Time (JIT) access to limit permanent privileged access.
Source: Computing.co.uk

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *