Azure Employee Directories Dumped via Stolen Access

Help Net Security · Medium sophistication
Last updated August 18, 2026

A threat actor called “TheHatman” claims they stole and posted large internal employee directories from multiple Fortune 500 companies’ Microsoft Azure tenants. Hudson Rock says the leaked samples look like real Azure directory exports, but the exact way the attacker got in is still unclear. One company (TCS) says it found no credible evidence of a breach and claims the attacker described using password spraying and “MFA fatigue.”

Key findings

  • A threat actor (“TheHatman”) claims to have extracted and posted large internal employee directories from multiple companies’ Azure tenants.
  • Hudson Rock reviewed samples and says the data appears consistent with a standard Azure directory export, but the intrusion method is not confirmed.
  • Possible access paths mentioned include infostealer-compromised session tokens, phishing leading to admin access, weak/insufficient MFA on certain tenant portals, or abuse of a third-party integration with excessive read permissions.
  • Leaked directories reportedly include org charts, group memberships, service accounts, and sometimes names of Global Administrators, information that can enable follow-on spear-phishing and impersonation attacks.
  • TCS stated it found no credible evidence of a breach and said the attacker claimed to use password spraying and MFA fatigue; TCS said it has controls against those techniques.

Who’s being targeted

  • Commonly targeted roles: All employees, IT administrators, Identity & Access Management (IAM) team, Helpdesk/Service Desk, Security Operations (SOC).
  • Affected industries: Information technology services, Telecommunications, Hospitality (hotels), Retail (apparel), Quick-service restaurants.
  • Attack channels: website.
  • Impersonated: Employee’s own corporate sign-in/MFA system (no human impersonation; attacker abuses normal prompts).

Awareness takeaways

  • Treat unexpected MFA prompts as a potential attack, deny them and report immediately.
  • Reduce exposure of admin identities and service accounts, because attackers can use that information to craft targeted scams.
  • Assume stolen credentials and session tokens are a realistic risk; prioritize infostealer and credential-theft defenses (endpoint protection, token revocation, conditional access).

Red flags to watch for

  • Multiple unexpected MFA prompts in a short period
  • Prompts appear when the user is not trying to log in
  • User feels pressured to ‘make it stop’ by approving
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine waking up to see our entire Azure employee directory dumped online, org chart, service accounts, even Global Admin names. That’s what a user called “TheHatman” claims they did to multiple Fortune 500 Azure tenants, likely off one bad login, then pulling a full Azure directory export. One path they brag about: password spraying plus “MFA fatigue”, hammering your account until your phone keeps buzzing, hoping you finally tap Approve just to make it stop. If your phone pops MFA prompts and you’re not logging in, that’s the attack: hit Deny every time and report it to IT immediately.

Similar attacks

BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
BigBear 2.0 Steals M365 Sessions to Bypass MFA

BigBear 2.0 Steals M365 Sessions to Bypass MFA

Researchers say the “BigBear 2.0” phishing-as-a-service operation compromised Microsoft 365 accounts by stealing authenticated session cookies after users completed MFA normally. This let attackers replay the session and access accounts without triggering another MFA prompt, impacting 258…

September 8, 2026
EvilTokens Used Device-Code Phish + AI for BEC

EvilTokens Used Device-Code Phish + AI for BEC

Microsoft disrupted EvilTokens, a phishing-as-a-service operation linked to thousands of compromised Microsoft 365 inboxes. The group used “device code” phishing to steal valid session tokens (not passwords) and then used an AI chatbot to scan mailboxes and help craft business email compromise…

September 22, 2026
BigBear 2.0 Steals M365 Sessions After MFA

BigBear 2.0 Steals M365 Sessions After MFA

CloudSEK reported a phishing-as-a-service operation (“BigBear 2.0”) that tricks Microsoft 365 users into signing in and completing MFA on a lookalike login page. Even though MFA succeeds, the attackers capture the authenticated session cookie and reuse it to access the victim’s Microsoft 365…

September 8, 2026
Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

Mirage2FA Phishing Kit Steals Microsoft 365 Sessions

A phishing-as-a-service toolkit called Mirage2FA has been targeting organizations by abusing real Microsoft 365 login pages through a man-in-the-middle proxy. The attackers capture usernames, passwords, and live two-factor authentication codes, then take over the user’s session using stolen session…

August 31, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026