Azure Employee Directories Dumped via Stolen Access

Help Net Security · Medium sophistication
Last updated August 18, 2026

A threat actor called “TheHatman” claims they stole and posted large internal employee directories from multiple Fortune 500 companies’ Microsoft Azure tenants. Hudson Rock says the leaked samples look like real Azure directory exports, but the exact way the attacker got in is still unclear. One company (TCS) says it found no credible evidence of a breach and claims the attacker described using password spraying and “MFA fatigue.”

Key findings

  • A threat actor (“TheHatman”) claims to have extracted and posted large internal employee directories from multiple companies’ Azure tenants.
  • Hudson Rock reviewed samples and says the data appears consistent with a standard Azure directory export, but the intrusion method is not confirmed.
  • Possible access paths mentioned include infostealer-compromised session tokens, phishing leading to admin access, weak/insufficient MFA on certain tenant portals, or abuse of a third-party integration with excessive read permissions.
  • Leaked directories reportedly include org charts, group memberships, service accounts, and sometimes names of Global Administrators, information that can enable follow-on spear-phishing and impersonation attacks.
  • TCS stated it found no credible evidence of a breach and said the attacker claimed to use password spraying and MFA fatigue; TCS said it has controls against those techniques.

Who’s being targeted

  • Commonly targeted roles: All employees, IT administrators, Identity & Access Management (IAM) team, Helpdesk/Service Desk, Security Operations (SOC).
  • Affected industries: Information technology services, Telecommunications, Hospitality (hotels), Retail (apparel), Quick-service restaurants.
  • Attack channels: website.
  • Impersonated: Employee’s own corporate sign-in/MFA system (no human impersonation; attacker abuses normal prompts).

Awareness takeaways

  • Treat unexpected MFA prompts as a potential attack, deny them and report immediately.
  • Reduce exposure of admin identities and service accounts, because attackers can use that information to craft targeted scams.
  • Assume stolen credentials and session tokens are a realistic risk; prioritize infostealer and credential-theft defenses (endpoint protection, token revocation, conditional access).

Red flags to watch for

  • Multiple unexpected MFA prompts in a short period
  • Prompts appear when the user is not trying to log in
  • User feels pressured to ‘make it stop’ by approving
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine waking up to see our entire Azure employee directory dumped online, org chart, service accounts, even Global Admin names. That’s what a user called “TheHatman” claims they did to multiple Fortune 500 Azure tenants, likely off one bad login, then pulling a full Azure directory export. One path they brag about: password spraying plus “MFA fatigue”, hammering your account until your phone keeps buzzing, hoping you finally tap Approve just to make it stop. If your phone pops MFA prompts and you’re not logging in, that’s the attack: hit Deny every time and report it to IT immediately.

Similar attacks

BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Fake GitHub Page Tricks Mac Users Into Malware

Fake GitHub Page Tricks Mac Users Into Malware

Researchers found a real macOS malware campaign that uses a fake GitHub download page to convince users to paste a command into Terminal and enter their Mac password. The malware then steals credentials, cookies, and files, and can even turn the victim’s Chromium browser into a remotely controlled…

August 17, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
RingCentral Breach Fuels Spoofed M365 Phish Risk

RingCentral Breach Fuels Spoofed M365 Phish Risk

Have I Been Pwned says the RingCentral incident exposed 1.6 million email addresses plus names, phone numbers, and physical addresses, which can make targeted phishing more convincing. Separately, researchers described spoofed RingCentral emails that bypassed defenses due to allowlisting and led…

August 14, 2026
FBI Warns: Athletes Hit With Fake Support Phishing

FBI Warns: Athletes Hit With Fake Support Phishing

The FBI and NCAA warned that criminals are breaking into college athletes’ online accounts to steal intimate photos and then use them for sextortion, harassment, or selling online. The article describes common entry methods like fake “customer support” password-reset requests and credential abuse,…

August 12, 2026
FBI: Sextortion Hackers Steal Photos via Fake Support

FBI: Sextortion Hackers Steal Photos via Fake Support

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell them online, often bundled with personal details. The advisory describes common social-engineering lures, like fake customer-service texts and phishing emails, that trick people into…

August 12, 2026