Connect with us

CyberSecurity

Fortune 500 Firms Hit in Azure Data Theft Campaign: Millions of Employee Records for Sale

Published

on

Azure data theft

Millions of Records from Corporate Giants Up for Sale

A cybercriminal operating under the alias ‘TheHatman’ is hawking what appears to be a treasure trove of corporate data — millions of employee records allegedly pulled directly from the Microsoft Azure tenants of some of the world’s most recognizable brands.

The list of supposedly affected companies reads like a who’s who of the Fortune 500: McDonald’s, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. If the claims hold up, this is a massive Azure data theft incident with far-reaching implications.

Security research firm Hudson Rock, which first flagged the campaign, says the stolen data appears to be the real deal. The datasets contain internal employee directories that line up with Azure directory exports based on email addresses and field names.

What’s in the Stolen Data?

The sheer volume is staggering. The McDonald’s dump alone reportedly contains over 1.7 million records. TCS follows with 800,000, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000.

Across all the affected tenant dumps, the leaked fields are consistent — and they’re not just names and email addresses. The exfiltrated information includes:

  • Employee names and corporate email addresses
  • Physical addresses and phone numbers
  • Employee IDs and job titles
  • Manager details and user group membership
  • Service accounts and highly privileged account records

That last bullet point is what keeps security professionals up at night. Hudson Rock notes that the exposure of service accounts and global admin names is particularly concerning, as it provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations.

How Did This Happen?

According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials. Hudson Rock’s analysis supports this theory — the firm identified stolen credentials linked to most of the affected organizations, likely compromised in a targeted infostealer campaign.

The victimology suggests this wasn’t a random smash-and-grab. The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics. That’s a deliberate pattern, not a scattergun approach.

The Infostealer Connection

Infostealer malware has become the bane of enterprise security. These malicious programs quietly siphon credentials from infected devices, often going unnoticed for months. When those credentials belong to employees with access to cloud infrastructure, the results can be catastrophic — as this campaign demonstrates.

Immediate Threats to Victim Organizations

Hudson Rock warns that the stolen data poses an immediate threat to the affected companies. Attackers can now map internal reporting structures and identify high-value targets. That’s the kind of intelligence that makes spear-phishing and business email compromise (BEC) attacks far more convincing.

Think about it: an email that appears to come from your actual manager, referencing your actual project, with your actual phone number in the signature block. That’s not a generic phishing attempt — that’s a precision strike.

For more on how similar incidents unfold, check out our coverage of the RingCentral data breach and the massive password spray campaign targeting Azure CLI.

What Organizations Should Do Now

While the full scope of this Azure data theft campaign is still unfolding, there are immediate steps companies should consider:

  1. Audit Azure AD and Entra ID logs for suspicious activity, especially around service accounts and privileged roles.
  2. Rotate credentials for any accounts that may have been exposed, particularly global admins.
  3. Enforce multi-factor authentication (MFA) across all user accounts, especially privileged ones.
  4. Monitor for infostealer infections on employee devices, as these often precede cloud account compromises.
  5. Review user group memberships and remove unnecessary access rights.

The fact that this data is already being sold on underground forums means the window for preventive action is closing fast. For the affected organizations, the focus now shifts to damage control and threat intelligence.

Hudson Rock’s findings also serve as a stark reminder that cloud security is only as strong as the credentials protecting it. A single compromised laptop can unravel an entire enterprise’s defenses.

As the investigation continues, expect more details to emerge about how TheHatman pulled off this audacious heist — and what it means for the future of cloud security.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

The Race to Field Military Autonomy Is On. Can Trusted Information Infrastructure Keep Pace?

Published

on

trusted information infrastructure

A New Kind of Arms Race

The pressure to field autonomous military systems has never been higher. Across the U.S., UK, and NATO, defense leaders are pouring money into programs that promise to move from concept to deployment at something close to commercial speed.

But there’s a catch. The hardware — drones, ground vehicles, loitering munitions — often gets the headlines. The real bottleneck sits deeper: the trusted information infrastructure that these systems depend on to function safely, securely, and reliably in contested environments.

That infrastructure includes secure data links, resilient command-and-control networks, and the software pipelines that feed AI models with trustworthy data. Without it, autonomy is just a liability.

Why Speed Is Trumping Caution

Traditional defense acquisition was built for a slower era. Programs took a decade or more, with rigid milestones and exhaustive testing. That model is cracking under the weight of new threats.

Adversaries are fielding autonomous systems faster than Western allies can respond. China and Russia have invested heavily in swarming drones and AI-enabled targeting. The U.S. Department of Defense responded by creating the Replicator initiative, aiming to field thousands of attritable autonomous systems in under two years. The UK has its own ambitious programs, and NATO is pushing for interoperability at scale.

The result is a race where speed is the metric that matters. But speed without trust is dangerous.

The Trust Problem: Data, Links, and Vulnerabilities

Autonomous systems are only as good as the data they consume. If a drone’s navigation feed is spoofed, or its target identification model is poisoned with bad training data, the consequences are catastrophic.

Trusted information infrastructure means more than just encryption. It requires:

  • Resilient communication links that survive jamming and cyberattacks
  • Verified data provenance, so AI models know where their inputs came from
  • Secure software supply chains, from code repositories to the final fielded build
  • Human oversight mechanisms that can intervene when systems behave unpredictably

Each of these is hard on its own. Together, they form a web of requirements that many fast-moving programs are struggling to meet.

What the U.S., UK, and NATO Are Actually Doing

The U.S. military has made trusted information infrastructure a priority in its joint warfighting concept. The Combined Joint All-Domain Command and Control (CJADC2) effort aims to connect sensors, shooters, and command centers across all services. But progress has been uneven, with service-specific programs often duplicating efforts.

The UK’s Defence Digital strategy focuses on similar goals, emphasizing secure data sharing across platforms and with allies. NATO, meanwhile, is working on standards for data interoperability — a critical piece that often gets overlooked until exercises reveal how hard it is to share information across national systems.

All three are experimenting with agile acquisition pathways, but the gap between rhetoric and fielded capability remains wide.

The Hardest Part: Testing and Certification

You can build an autonomous system in a lab. Certifying it for real-world use is another matter entirely.

Testing autonomy requires simulating millions of scenarios, including adversarial attacks on the information infrastructure itself. How does a system behave when its GPS is jammed, its datalink is cut, or its sensor feed is flooded with false data? These are not hypothetical questions. They are the core of what makes autonomy trustworthy.

Current certification frameworks were designed for human-in-the-loop systems. They don’t easily accommodate the complexity of AI-driven decision-making. Defense agencies are scrambling to develop new assurance methods, but they are lagging behind the pace of deployment.

What Needs to Happen Next

The race won’t slow down. Adversaries are not waiting for the West to perfect its infrastructure. So the question becomes: how do you accelerate without compromising trust?

One answer is modularity. Build systems with open standards and plug-and-play interfaces, so that new capabilities can be integrated without rewriting the entire stack. Another is investment in cyber resilience from the start, not as an afterthought.

Most importantly, defense leaders need to treat trusted information infrastructure as a first-class requirement, not a support function. That means funding it, testing it, and holding programs accountable for it — just as rigorously as they hold them accountable for speed.

The military autonomy race is real, and it’s moving fast. But the winner won’t be the side with the most drones. It will be the side that can trust its own systems when it matters most.

Continue Reading

CyberSecurity

EU Orders Google to Open Android’s Mic, Camera and Screen to Rival AI Assistants

Published

on

Android rival AI assistants

Brussels turns the screws on Google’s Android dominance

The European Commission has dropped a bombshell on Google. On Thursday, it ordered the tech giant to hand rival AI assistants the same deep access to Android that Gemini enjoys. That means the microphone, the camera, whatever’s on screen, a wake word that works even when the display is off, and the ability to mimic taps and typing to drive other apps in the background.

The deadline is tight. Google must ship this in the next major release, Android 18, and no later than 1 August 2027. For a company used to setting its own timelines, that’s a seismic shift.

What exactly did the EU order?

The Commission’s decision is a direct response to the Digital Markets Act (DMA), which designates Google as a “gatekeeper” platform. Under the DMA, gatekeepers can’t favour their own services over rivals’. By keeping Gemini’s Android privileges exclusive, the EU argues, Google was doing precisely that.

Concretely, Google now has to open up several core Android capabilities to third-party assistants. These include:

  • Microphone and camera access – so a rival assistant can hear and see what the user sees, just like Gemini.
  • Screen content – allowing assistants to read what’s displayed, which is crucial for contextual help.
  • Wake word with screen off – so users can summon a rival assistant hands-free, even when the device is idle.
  • Background app control – the ability to simulate taps and typing to operate other apps, a feature that’s long been a Gemini advantage.

These aren’t trivial permissions. They’re the very tools that make an AI assistant genuinely useful. Without them, rivals are effectively flying blind.

Why this matters for the AI assistant wars

The stakes here go far beyond Android. This ruling is about who gets to be the default interface between humans and their phones. If Gemini is the only assistant that can see your screen and act on it, then Google owns the entire AI layer on Android. Rivals like OpenAI’s ChatGPT, Anthropic’s Claude, or even European startups are left scrambling for scraps.

The Commission’s move levels that playing field. It forces Google to treat third-party assistants as equals, not as threats to be suffocated. For consumers, that could mean real choice. Imagine asking a rival assistant to book a ride, order food, or summarise an email, all with the same hands-free, context-aware power that Gemini users already take for granted.

Google’s response: compliance or fight?

Google hasn’t publicly committed to the timeline yet, and the company has a history of appealing such decisions. The DMA itself is still being tested in courts across Europe, and Google could argue that opening up Android’s core to rivals poses security risks.

But the Commission has been clear: the technical measures are feasible, and the deadline is non-negotiable. If Google misses it, the fines can reach up to 10% of its global turnover. That’s a serious incentive to comply.

What this means for Android users

For the average user, this is a win. More competition in the assistant space usually means better features, faster innovation, and lower prices. You’ll no longer be locked into Gemini just because it’s pre-installed. You’ll be able to pick your assistant the way you pick your keyboard or browser.

That said, there’s a catch. Deep system access raises privacy questions. If a rival assistant can read your screen and hear your calls, that’s a lot of trust to place in a third party. The EU has addressed this by requiring user consent and transparency, but the practical implementation will be worth watching.

The bigger picture: Europe’s tech sovereignty push

This ruling fits a broader pattern. Brussels has been aggressively regulating Big Tech, from DMA compliance for app stores to data privacy enforcement under GDPR. The message is simple: if you want to operate in Europe, you play by European rules.

Whether that’s good for innovation or just bureaucratic meddling is a matter of debate. But one thing’s certain: Android is about to become a lot more open, and the AI assistant race just got a whole lot more interesting.

For now, developers of rival assistants should start preparing. The Android 18 SDK is coming, and the door is finally open. The question is who’ll walk through it first.

Continue Reading

CyberSecurity

Nvidia and Tech Giants Launch Open Secure AI Alliance to Arm Defenders

Published

on

AI security alliance

A Coalition Takes Shape

On Monday, Nvidia and more than 30 technology, cybersecurity, and enterprise software heavyweights announced the formation of the Open Secure AI Alliance. The goal? Build and share open source tools, models, and techniques for securing AI systems and agents.

The alliance builds on earlier work from the Linux Foundation’s Akrites initiative and the OpenSSF community. It’s a recognition that AI security can’t stay locked inside proprietary labs.

Who’s In

The inaugural partner list reads like a who’s who of tech. Adobe, Cisco, Cloudflare, CrowdStrike, Databricks, Dell, IBM, Microsoft, Palo Alto Networks, Red Hat, Salesforce, SAP, Snowflake, and Hugging Face are all in. So are Capital One, Cloudera, Cognition, DoorDash, Elastic, HPE, LangChain, Naver, NetApp, Nous Research, OpenClaw, Palantir, Reflection AI, ServiceNow, Siemens, SK Telecom, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI.

That’s a broad tent. Banks, cloud providers, chipmakers, security vendors, and AI startups — all agreeing on one thing: defenders need better tools.

What Each Giant Is Bringing

Nvidia’s contribution includes open models, weights, data, and agent harness research. The company also released a new open source project called NOOA, designed to help harnesses make agent behavior easier to trace, test, and audit.

HPE is contributing to SPIFFE/SPIRE, a zero-trust identity framework for cryptographically verifying AI agents and services. Hugging Face is donating its Safetensors model weight storage format to the PyTorch Foundation.

IBM and Red Hat are extending open source supply chain security through the Lightwell project, which aims to deliver automated vulnerability remediation at scale. Microsoft is contributing MDASH, a multi-model agentic scanning harness that coordinates AI agents to find, debate, and validate exploitable software bugs. SpaceXAI is open-sourcing its Grok Build terminal-based AI coding agent, with plans to eventually open-source the weights of the Grok model line.

Why Openness Matters Now

The alliance’s core argument: open models, harnesses, and security tooling should be treated as defensive assets, not liabilities. The group warns policymakers and regulators that broad restrictions on open frontier AI could weaken collective cyber defense capacity.

Nvidia points to a recent security incident involving OpenAI and Hugging Face. When closed AI tools couldn’t differentiate between attackers and defenders and blocked forensic work, Hugging Face used the open-weight GLM 5.2 model on its own systems to review over 17,000 actions and contain the breach.

“The right response is not to deny defenders access to capable open systems,” Nvidia said. “It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies.”

“Defenders need both frontier closed models and frontier open models, working together,” the company added, “so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them.”

What This Means for Security Teams

For practitioners, the alliance could mean more options when it comes to AI security testing. Open harnesses like NOOA and MDASH give teams the ability to probe their own AI systems without waiting for a vendor’s patch cycle.

The zero-trust identity work from HPE on SPIFFE/SPIRE also matters. As AI agents become more autonomous, verifying who — or what — is making decisions becomes critical. Cryptographic identity for agents isn’t a nice-to-have anymore.

The supply chain angle is worth watching too. Lightwell’s automated vulnerability remediation could help close the gap between discovery and patching, a problem that’s only getting worse as AI-generated code accelerates development cycles.

The Bigger Picture

This launch lands amid a broader push on AI security. The White House recently launched an AI-driven vulnerability coordination initiative called ‘Gold Eagle.’ Meanwhile, researchers keep finding flaws in AI systems — from ChatGPT agent vulnerabilities to nuclear-sabotage malware benchmarks that trip up frontier models.

The AI security alliance is a bet that openness will win. It’s also a direct challenge to the idea that keeping powerful AI models locked away makes the world safer. The alliance’s answer: locked models leave defenders blind.

Whether that argument sways regulators remains to be seen. But for now, the tools are coming. Open source, auditable, and ready for defenders to use.

Continue Reading

Trending