Data BreachBleeping Computer
8.0 — CRITICAL
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A threat actor, identified as 'TheHatman', claimed to have stolen 3.64 million employee records from major companies using compromised credentials on Microsoft Azure infrastructure. The stolen data includes names, email addresses, job titles, phone numbers, and other tenant account records.
⚙️Technical Details
Affected Systems
Microsoft Azure
Attack Vectors
Compromised credentialsPassword sprayMulti-Factor Authentication (MFA) fatigue
💥Impact Assessment
Severity: high
Who Is at Risk
Employees of affected companiesCompanies with Azure infrastructureSeverity: high
🛡️Recommended Actions
1Implement multi-factor authentication for all users
2Regularly review and update passwords
3Monitor Azure infrastructure for suspicious activity
📦Affected Products
Microsoft Azure
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
