logo

Crook hawks millions of records allegedly plundered from corporate Azure tenants

ID: 1f871bc4-9ce7-5c0f-aded-17e225f43c33

STIX ID: report--1f871bc4-9ce7-5c0f-aded-17e225f43c33

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-08-17

Date Updated: 2026-08-17

...
...

A threat actor using the handle "TheHatman" claims to be selling millions of employee records allegedly taken from Microsoft Azure/Entra directories of nine large organizations (including McDonald's, Vodafone, TCS, Kyndryl and others). Research by Hudson Rock judged the sample data likely authentic and found sensitive fields — phone numbers, addresses, employee IDs, group memberships and some Global Administrator attributions — that could enable targeted phishing or account takeover; the initial access vector is unclear but researchers suspect infostealer-compromised credentials, phishing, weak MFA, or permissive third-party apps, while some affected companies say the data may be older or there is no evidence of a current breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.