Hacker Claims 3.6 Million Azure Account Records Stolen from Major Companies
A hacker is claiming to have stolen 3.6 million account records tied to Microsoft Azure — Microsoft's cloud computing platform used by businesses worldwide — from a number of large organisations, according to Bleeping Computer.
The details available are limited, but the scale of the claim is significant. Azure underpins the login infrastructure, storage, and internal tools for companies across every major industry. If the records are genuine, the exposed data could include account credentials and other identifiers that attackers use to gain further access — think of it like getting a master key list for a building, then working out which doors each key opens.
What is not yet confirmed: whether the data has been verified, which companies are affected, or exactly how the records were obtained.
That uncertainty is not a reason to wait. If you use any service that runs on Azure infrastructure — which covers a broad sweep of enterprise software — now is a good time to change passwords for work accounts, enable multi-factor authentication (MFA) where it is not already active, and watch for any unexpected login alerts.
What to do: Change passwords on any work or business accounts, enable MFA on everything you can, and check your email for breach notification messages over the coming days.
Sources

