Fortune 500 Azure/Entra ID data theft (TheHatman)
A threat actor using the handle TheHatman advertised roughly 3.64 million employee directory records scraped from the Microsoft Azure and Entra ID tenants of multiple Fortune 500 companies, with access reportedly gained through stolen credentials harvested by infostealer malware.
- Victim
- Multiple Fortune 500 companies (Azure/Entra ID tenants)
- Records
- 3.6M