The week of 17 to 23 August 2026 was defined by stolen and sprayed credentials doing the work that malware used to do. France’s tax authority DGFiP confirmed that attackers used compromised access points to extract data on 678,000 individuals. A threat actor calling themselves TheHatman put 3.64 million employee records from Fortune 500 Azure tenants up for sale, with Tata Consultancy Services naming password spraying and MFA fatigue as the technique. The University of Texas at San Antonio took its network offline and delayed the fall semester for more than 42,000 students. CISA, the FBI, and HHS updated their Medusa ransomware advisory to more than 500 critical infrastructure victims, and the US Department of Justice charged 17 Iranians over a 31-terabyte academic theft campaign built on spearphishing and password sprays. The through-line is identity: four of the five stories start with a valid credential in the wrong hands, not an exploit.
1. France’s tax authority DGFiP confirms breach of 678,000 taxpayers’ records
Overview: On 17 August 2026, France’s Ministry of the Economy and Finance confirmed that attackers accessed systems of the General Directorate of Public Finances (DGFiP) and extracted personal tax data on 678,000 individuals and professionals, following a claim posted by a threat actor called ZeroBytes on 12 August 2026.
Impact: 678,000 individuals and professionals had tax reference income, family quotient, withholding tax rates, and cadastral data including addresses and property sizes exposed. The actor separately claimed access to roughly 20 million records on the French land registry platform, of which 252,149 were claimed stolen; DGFiP has not confirmed those land registry figures. The ministry states that user credentials and online tax accounts were not compromised.
Details: The ministry said existing access points were used to consult and extract data, and it has not published the initial entry vector. France’s national cybersecurity agency ANSSI is assisting the investigation, and the CNIL was notified when the breaches were identified. What the disclosure stops short of confirming matters: no entry vector, no dwell time, and no confirmation or denial of the land registry claims. Use of valid access paths for collection maps to MITRE ATT&CK T1078, Valid Accounts.
Remediation guidance: Inventory every externally reachable access point into tax, finance, and citizen-data systems, including partner and API paths, and test each one from the attacker’s side. Alert on bulk read and export volumes per account, not only on login anomalies. Rehearse the regulator notification path so disclosure lags discovery by days, not weeks.
2. TheHatman claims 3.64 million employee records stolen from Fortune 500 Azure tenants
Overview: Between 31 July and 16 August 2026, a threat actor using the alias TheHatman claimed to have downloaded 3.64 million employee records directly from the Azure tenants of McDonald’s, Vodafone, Tata Consultancy Services, Kyndryl, HCL Technologies, InterContinental Hotels, Gap Inc., and others, with the claims surfacing publicly on 17 and 18 August 2026.
Impact: The actor’s claimed per-company counts include more than 1.7 million records from McDonald’s, 800,000 from TCS, 425,000 from Vodafone, and 170,000 from Kyndryl. These are the actor’s numbers, not confirmed figures. TCS disputes the claim and says the sampled data appears at least four years old; Gap Inc. found no evidence of a breach and calls the data non-sensitive and dated. McDonald’s and Vodafone had not responded at the time of reporting.
Details: TCS’s own statement is the most useful technical fact in the story: the attacker used password spraying and MFA fatigue, which map to MITRE ATT&CK T1110.003 and T1621. No Azure platform vulnerability is asserted by anyone; the claimed access path is valid credentials plus a worn-down second factor. Treat every count in this story as a claim until a victim files or confirms.
Remediation guidance: Replace push-based MFA approval with number matching or phishing-resistant FIDO2 on all tenant admin and privileged accounts. Test your own tenant against password spraying from outside, at the cadence attackers run it, not annually. Set conditional access to block legacy authentication paths that bypass MFA entirely.
3. UT San Antonio takes network offline, delays fall semester for 42,000 students
Overview: On 19 August 2026, the University of Texas at San Antonio announced it had detected an attempted intrusion at the edge of its network over the preceding weekend, took systems offline as a precaution, and delayed the start of the fall semester from 19 August to 24 August 2026.
Impact: More than 42,000 students lost three instructional days. Phone systems, the password reset tool, and network access were disrupted while University Technology Solutions reviewed systems. The university states there is no evidence data was taken and that the activity was stopped before it reached core systems; Texas Cyber Command was engaged on the incident.
Details: UTSA has not named the intrusion method or an actor, and the public record is the university’s own statements from President Taylor Eighmy and COO Andrea Marks. The interesting fact is the cost asymmetry: an intrusion the university describes as caught at the edge still forced a five-day operational delay, because the containment response, not the attacker, took the systems down. The disclosure stops short of saying what the edge device or service was.
Remediation guidance: Map which business operations halt when you pull each edge system, before an incident forces the choice. Pre-stage out-of-band communications so phone and password-reset outages do not compound the disruption. Test edge-facing services continuously, since that is where this activity was caught.
4. CISA, FBI, and HHS update Medusa advisory: more than 500 critical infrastructure victims
Overview: On 19 August 2026, CISA, the FBI, and HHS updated joint advisory AA25-071A on Medusa ransomware, reporting that the operation has compromised more than 500 critical infrastructure organizations since June 2021, a milestone reached as of April 2026.
Impact: Victims span healthcare and public health, the defense industrial base, critical manufacturing, government facilities, IT, and financial services. Medusa runs double extortion, and the advisory puts affiliate payments for initial access at between $100 and $1 million. The update follows continued attacks on healthcare organizations, which is why HHS is a co-author.
Details: Medusa’s model is ransomware-as-a-service with initial access outsourced to brokers recruited on criminal forums. Access is bought, not engineered: the brokers trade in stolen credentials and unpatched internet-facing services, then affiliates move laterally to encryption and exfiltration. That makes the entry point a market, and it maps to MITRE ATT&CK T1078 and T1190 depending on what the broker sold. The advisory’s core asks are vulnerability remediation, segmentation, and blocking untrusted remote access paths.
Remediation guidance: Patch internet-facing services on the cadence brokers scan them, which is days, not quarterly windows. Segment so a purchased foothold cannot reach backup and management planes. Require phishing-resistant MFA on every remote access path, including vendor VPN accounts.
5. US charges 17 Iranians over 31-terabyte, 144-university credential theft campaign
Overview: On 18 August 2026, the US Department of Justice announced a superseding indictment charging 17 members of Iran’s Mabna Institute over a campaign that stole more than 31 terabytes of academic data and intellectual property between roughly 2013 and at least December 2017, adding 8 defendants to the 9 first charged in March 2018.
Impact: The campaign compromised 144 US universities, 178 foreign universities across 21 countries, more than 42 US private sector companies, at least 11 foreign companies, 5 US federal and state agencies, and 2 NGOs. The 14-count indictment includes conspiracy to commit computer intrusions, wire fraud, computer fraud, and aggravated identity theft, with maximum sentences of 2 to 20 years per charge.
Details: The DOJ describes the tradecraft plainly: spearphishing of professor accounts, password spray attacks, and reuse of stolen credentials, on behalf of the Islamic Revolutionary Guard Corps. That is MITRE ATT&CK T1566 and T1110.003, the same pair carrying this week’s Azure claims, run at nation-state scale for four years. The defendants remain outside US custody, so the practical effect is indictment as public attribution rather than imminent prosecution.
Remediation guidance: Treat faculty, researcher, and contractor identities as privileged accounts, since their access aggregates into terabytes. Run password spray simulations against your own identity provider from external infrastructure. Monitor for credential replay from anomalous ASNs, not just impossible travel.
Related reading
- Coupang data breach analysis, because this week’s DGFiP and Azure stories repeat the same pattern of credential-driven access and delayed detection at scale.
- The Great AI Divide in cybersecurity, for the widening gap between attacker speed and annual testing cadence that the Medusa access-broker economy exploits.
How FireCompass helps
Four of this week’s five stories start with identity: sprayed passwords, fatigued MFA, phished professors, and purchased footholds, against organizations that did not know which of their access points an attacker would try first. FireCompass takes the attacker’s route instead: its agentic AI platform discovers your internet-facing surface, then runs AI-native web application and API pentesting against what it finds, validating each finding with proof of exploitability at a false positive rate of under 2 percent, against 40 to 70 percent for scanners. CVEs are exploited in about 3 days while most programs test annually; a continuous testing cadence is what closes that gap before an access broker prices your perimeter.
Ready to see what an attacker would find on your perimeter this week, not once a year?
Frequently asked questions
What was the biggest cyberattack this week (17 to 23 Aug 2026)?
The DGFiP breach was the week’s most consequential confirmed incident: France’s tax authority confirmed on 17 August 2026 that attackers extracted tax data on 678,000 individuals and professionals, including income references and property records, with the entry vector still unpublished.
Was McDonald’s really breached through Azure?
Not confirmed. A threat actor called TheHatman claims 3.64 million employee records from Azure tenants including McDonald’s and Vodafone, but as of 18 August 2026 no victim has confirmed; TCS disputes the claim, saying its sampled data is at least four years old, and Gap found no evidence of a breach.
Why did UTSA delay the fall 2026 semester?
UT San Antonio detected an attempted intrusion at the edge of its network the weekend of 17 August 2026 and took systems offline as a precaution. The containment response disrupted phones and network access, so the university moved the semester start from 19 to 24 August for its more than 42,000 students.
How many organizations has Medusa ransomware hit?
More than 500 critical infrastructure organizations since June 2021, according to the updated CISA, FBI, and HHS advisory AA25-071A published 19 August 2026. Victims span healthcare, defense, manufacturing, government, IT, and financial services, with initial access typically bought from brokers on criminal forums.
What was the common attack pattern this week?
Credential abuse. The DGFiP breach used existing access points, the Azure claims rest on password spraying and MFA fatigue, and the Mabna indictment of 18 August 2026 details spearphishing plus password sprays across 144 US universities. Four of five stories needed a valid credential, not an exploit.
How do I defend against password spraying and MFA fatigue?
Enforce number matching or FIDO2 instead of push approvals, block legacy authentication, and test your identity perimeter from outside at the cadence attackers do. Password spraying succeeded in campaigns from 2013 through this week’s claims; 22 percent of breaches start with credential abuse, so treat it as your most probable entry vector.
