Hacker claims millions of records stolen from corporate Azure tenants
ID: e5160a3a-1420-565b-8b4e-a09d83a9d4ff
STIX ID: report--e5160a3a-1420-565b-8b4e-a09d83a9d4ff
Feed Name: Help Net Security
A threat actor calling itself “TheHatman” claims to have leaked millions of employee records from Azure tenants of multiple large companies (including McDonald’s, TCS, Vodafone, HCL, and others); Hudson Rock reviewed samples that appear consistent with Azure directory exports and warns the dumps include employee IDs, roles, group memberships, service accounts, and some global admin names, enabling targeted phishing or privilege escalation. Researchers suspect the exfiltration likely stems from infostealer infections, credential compromise, or misuse of third-party integrations rather than an Azure zero-day; affected organizations are investigating, and TCS states it found no credible evidence of a recent breach.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
