Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
Palo Alto Networks, Tuesday, August 18th, 2026
Unit 42 updates guidance after an actor claimed to have stolen large volumes of credentials from Microsoft Entra tenants.
Palo Alto Networks Unit 42 published an updated threat brief on large-scale credential attacks. In August 2026 an actor operating as TheHatman claimed to have stolen a large volume of credentials from organizations' Microsoft Entra tenants.
The brief provides guidance on mitigating attacks of this scale and shape. It covers detection considerations and the controls that limit blast radius once credentials are known to be exposed. The August 18 update reflects developments since the initial publication.