A threat actor called “TheHatman” claims they stole and posted large internal employee directories from multiple Fortune 500 companies’ Microsoft Azure tenants. Hudson Rock says the leaked samples look like real Azure directory exports, but the exact way the attacker got in is still unclear. One company (TCS) says it found no credible evidence of a breach and claims the attacker described using password spraying and “MFA fatigue.”
Key findings
- A threat actor (“TheHatman”) claims to have extracted and posted large internal employee directories from multiple companies’ Azure tenants.
- Hudson Rock reviewed samples and says the data appears consistent with a standard Azure directory export, but the intrusion method is not confirmed.
- Possible access paths mentioned include infostealer-compromised session tokens, phishing leading to admin access, weak/insufficient MFA on certain tenant portals, or abuse of a third-party integration with excessive read permissions.
- Leaked directories reportedly include org charts, group memberships, service accounts, and sometimes names of Global Administrators, information that can enable follow-on spear-phishing and impersonation attacks.
- TCS stated it found no credible evidence of a breach and said the attacker claimed to use password spraying and MFA fatigue; TCS said it has controls against those techniques.
Who’s being targeted
- Commonly targeted roles: All employees, IT administrators, Identity & Access Management (IAM) team, Helpdesk/Service Desk, Security Operations (SOC).
- Affected industries: Information technology services, Telecommunications, Hospitality (hotels), Retail (apparel), Quick-service restaurants.
- Attack channels: website.
- Impersonated: Employee’s own corporate sign-in/MFA system (no human impersonation; attacker abuses normal prompts).
Awareness takeaways
- Treat unexpected MFA prompts as a potential attack, deny them and report immediately.
- Reduce exposure of admin identities and service accounts, because attackers can use that information to craft targeted scams.
- Assume stolen credentials and session tokens are a realistic risk; prioritize infostealer and credential-theft defenses (endpoint protection, token revocation, conditional access).
Red flags to watch for
- Multiple unexpected MFA prompts in a short period
- Prompts appear when the user is not trying to log in
- User feels pressured to ‘make it stop’ by approving
Read the video transcript
Imagine waking up to see our entire Azure employee directory dumped online, org chart, service accounts, even Global Admin names. That’s what a user called “TheHatman” claims they did to multiple Fortune 500 Azure tenants, likely off one bad login, then pulling a full Azure directory export. One path they brag about: password spraying plus “MFA fatigue”, hammering your account until your phone keeps buzzing, hoping you finally tap Approve just to make it stop. If your phone pops MFA prompts and you’re not logging in, that’s the attack: hit Deny every time and report it to IT immediately.