Hacker claims millions of records stolen from corporate Azure tenants – Help Net Security

August 18, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: helpnetsecurity.com

Threat Risk: High
Victim: Fortune 500 Companies
Incident: Mass exfiltration of employee directories from multiple corporate Azure tenants.
Impact: Exposure of millions of employee records and administrator identities, facilitating targeted social engineering attacks.
Attacker: TheHatman
Analysis: The attacker is exfiltrating standard Azure directory exports, likely leveraging infostealer-compromised session tokens or MFA fatigue. The exposure of Global Administrator names and service accounts creates a high-risk roadmap for future targeted spear-phishing and privilege escalation. The scale and speed of the dumps suggest a systematic, automated approach to exfiltration.
Recommendations: Rotate session tokens and enforce phishing-resistant MFA to prevent session hijacking.; Audit Azure directory permissions and limit the visibility of administrative account names.; Monitor for unusual mass-export activities within Azure Active Directory/Entra ID.
Source: Help Net Security

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *