An account calling itself TheHatman spent the first half of August posting the same pitch on hacking forums: employee records, it said, pulled out of the Microsoft Entra tenants of a string of large companies. Palo Alto Networks' Unit 42 has now written the activity into its running brief on large scale credential attacks, and its position there is deliberately narrow. The sale posts are real. The break-ins behind them are not confirmed.
Between August 1 and August 17, Unit 42's threat brief says, the actor advertised employee information for multiple enterprises across several forums, claiming it had been exfiltrated from those organizations' Microsoft Entra tenants. Entra is the service that decides who gets into a company's Microsoft 365 and Azure estate, so its directory sits close to a staff roster with the access rights attached. TheHatman says it holds sensitive or confidential information from several high profile organizations, and that it got in using compromised credentials gathered through MFA fatigue (pushing login approval prompts at a target until one is accepted) and password spraying (trying a few common passwords across many accounts at once).
Unit 42 will not stand behind the claim
It says plainly that it has not verified the claims and has been unable to identify a specific intrusion vector. That distinction is worth holding on to, because a forum seller has every reason to make a pile of recycled credentials sound like a fresh intrusion, and buyers rarely audit. The activity was publicly reported as early as August 16, Unit 42 put out initial guidance on social media at the time, and the brief itself was updated on August 18.
That brief is a repository rather than a single investigation, and the company it keeps is instructive. The other campaign tracked in it is FortiBleed, the June password spraying wave against internet-facing Fortinet devices that also reached Sophos and MSSQL services, which we covered when the spraying first surfaced. Unit 42 assesses that the initial password list behind that campaign was likely developed from a mix of previous breaches, including successful exploitation of vulnerabilities, and that credentials cracked in each round are added back to the list for the next one. SOCRadar provided the initial reporting on the FortiGate targeting.
That loop is why a sale post deserves attention even when the intrusion behind it is unproven. Leaked pairs become spraying lists, spraying lists produce fresh access, and fresh access produces more pairs. A dump of 24 billion exposed credentials is not a historical curiosity inside that model. It is inventory.
Hunt for the login that follows the failures
Unit 42's first recommendation is a hunt rather than a control: audit remote access logs for successful logins that arrive shortly after a burst of failed ones. The hardening advice behind it is ordered sensibly. Require phishing resistant multi-factor authentication for all remote services. Keep management interfaces off the public internet, behind jump boxes or zero trust network access policies. Change default account credentials, and rotate privileged ones automatically. Run continuous discovery of privileged accounts and disable the ones nobody uses. Patch, including local privilege escalation bugs, since those are what turn a low value login into a device configuration dump.
Palo Alto Networks says it shared its findings with fellow Cyber Threat Alliance members, including Fortinet. For everyone else the practical reading is simpler: assume some of your staff credentials are already sitting on somebody's list, and make the password on its own worth nothing.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.