❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security

Hacker Claims Millions of Records Stolen From Azure Tenants

18 August 2026 at 10:57

A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks.

The threat actor, known as β€œTheHatman,” has reportedly posted internal employee directories belonging to companies including McDonald’s, Vodafone, Kyndryl, Tata Consultancy Services (TCS), HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies, and Wyndham Hotels for sale on cybercrime forums.

According to various sources, samples of the data contained corporate email addresses and fields consistent with standard Azure directory exports. However, the exact method used to gain access remains unconfirmed.

Researchers said compromised credentials linked to many of the affected organisations had previously circulated following infostealer infections. Possible routes into the environments include stolen session tokens, phishing, weak MFA protections, or third-party integrations with excessive permissions.

Employee data creates a roadmap for attackers

The allegedly stolen information includes employee IDs, job titles, departments, reporting structures, group memberships, service accounts, and, in some cases, details of Global Administrator accounts.

Cian Heasley, Principal Consultant at Acumen Cyber, warned that information that initially appears relatively harmless can provide the foundations for further attacks.

β€œNames, job titles, phone numbers, service account labels, and global administrator identities are precisely the precursors required to build convincing spear-phishing, phone based social engineering and helpdesk request employee impersonation attacks against higher value accounts or systems,” Heasley said.

He also warned against dismissing older employee information as irrelevant.

β€œEnterprise org charts change slowly, service account naming conventions rarely change and historic breached data dumps can remain useful for aiding in the planning and execution of new attacks years after the original compromise took place.”

TCS has said it found no credible evidence that its systems or customer environments were breached. The company said the referenced information appeared to be more than four years old and limited to basic employee details.

Stolen credentials put cloud environments at risk

Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, said the incident demonstrates how infostealer infections can ultimately lead to cloud compromise.

β€œInfostealers harvesting credentials from corporate devices, those credentials landing in criminal marketplaces, and a threat actor using them to access cloud environments that trusted those credentials without adequate verification. Same playbook. Different logos on the breach notification.”

Patel said cloud identity infrastructure is only as secure as the credentials and devices accessing it.

β€œConditional access policies, continuous access evaluation, device compliance checks, and real-time credential compromise detection are the controls that close the gap between β€˜credentials stolen by an infostealer’ and β€˜attacker inside your cloud environment.'”

He described the employee information reportedly being sold as a β€œprecision targeting kit” for spear phishing and executive impersonation.

Valid credentials should not mean unrestricted data access

Simon Pamplin, CTO at Certes, said the incident also raises questions about what attackers can do once legitimate credentials have been compromised.

β€œStolen credentials should not automatically mean stolen data. That is the real issue with this campaign,” Pamplin said.

β€œThe reported ability to use compromised credentials to extract huge volumes of information from enterprise cloud environments shows what can happen when successful authentication is effectively treated as permission to access and move data.”

Pamplin argued that organisations need to assume credentials will sometimes be stolen and ensure that compromising an identity does not automatically make sensitive information readable.

β€œCloud security needs to separate identity from control of the data itself. Sensitive data flows should be independently encrypted, segmented and governed so that compromising an account does not provide unrestricted movement across the environment.”

The incident also carries potential supply chain implications. Heasley pointed to the presence of major IT service providers among the organisations named, warning that businesses should review which suppliers hold privileged access to their environments.

The case is also a reminder that data theft does not always arrive with a ransom demand. In this instance, the threat actor appears to be attempting to sell the information directly, meaning affected organisations may only become aware of the theft once their data surfaces on criminal forums.

The post Hacker Claims Millions of Records Stolen From Azure Tenants appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the reportβ€˜s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

β€œAI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

β€œIn observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

β€œAs attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

β€œMany organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

❌
❌