← All Briefings
Briefings


Hacker Sells 3.6 Million Records Stolen From Azure Accounts

A threat actor is advertising 3.6 million employee records lifted from the Azure tenants of multiple Fortune 500 companies, obtained not through an Azure vulnerability but through compromised credentials at the account level. Microsoft's own guidance treats this class of intrusion as solved: conditional access policies, phishing-resistant MFA, and Entra ID risk-based sign-in controls are all documented, all available, and all optional. The seller's pitch to buyers is the tell. It advertises company names, not a CVE.

Credential theft against cloud tenancy does not trip the same disclosure wires as a platform flaw, so the companies named in the listing get to decide quietly whether they were ever breached at all. That decision now sits with security teams who configured Azure AD conditional access as a checkbox exercise rather than a default-deny posture. The next signal to watch is whether any Fortune 500 firm named in the criminal listing confirms it before regulators ask.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.