logo

Hacker claims millions of records stolen from corporate Azure tenants

ID: e5160a3a-1420-565b-8b4e-a09d83a9d4ff

STIX ID: report--e5160a3a-1420-565b-8b4e-a09d83a9d4ff

Feed Name: Help Net Security

Threat Score
72/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

Author: Sinisa Markovic

...
...

A threat actor calling itself “TheHatman” claims to have leaked millions of employee records from Azure tenants of multiple large companies (including McDonald’s, TCS, Vodafone, HCL, and others); Hudson Rock reviewed samples that appear consistent with Azure directory exports and warns the dumps include employee IDs, roles, group memberships, service accounts, and some global admin names, enabling targeted phishing or privilege escalation. Researchers suspect the exfiltration likely stems from infostealer infections, credential compromise, or misuse of third-party integrations rather than an Azure zero-day; affected organizations are investigating, and TCS states it found no credible evidence of a recent breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.