ThreatPaper
Assessed, Not Confirmed

The leaked Azure/Entra directory data is highly likely authentic

Assessment

This is the stated assessment of infostealer-intelligence firm Hudson Rock, which examined campaign samples and judged them 'highly likely authentic' from corporate email structures and field names consistent with Microsoft Azure/Entra directory exports, while explicitly adding it was 'not conclusive how this campaign is being carried out'. It is an assessment at a stated confidence, not independent confirmation of a current TCS breach, which TCS disputes; BleepingComputer and The Register could not independently verify the data. Treating 'authentic sample' as proof of a current TCS compromise is the error.

Where this claim appeared

Help Net Security · 2026-08-18

https://www.helpnetsecurity.com/2026/08/18/azure-data-leak-fortune-500-companies/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

TCS employee-directory leak claim: 800,000 records advertised by 'TheHatman', company finds no breach

Think this assessment is wrong? Report an error.