Azure Credential Breach Leaks Millions of Enterprise Directory Records

A threat actor named TheHatman is selling massive Azure/Entra tenant dumps containing employee records from multiple major companies, including McDonald’s (~1.7M) and Vodafone (~425k), exfiltrated via compromised credentials. The data fields cover names, corporate emails, phone numbers, addresses, job titles, departments, and privileged accounts, enabling targeted BEC and privilege escalation. While the exact intrusion vector isn’t confirmed, researchers link the leaks to Infostealer infections and credential abuse rather than a Azure zero-day. Defenders should monitor for credential exposure, enforce MFA, and review third-party access to Azure directories to mitigate risk.}
- Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials InfoStealers
- McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen Security Affairs
- TCS, HCL, Hexaware named in global Azure directory data leak linked to infostealers CRN Asia
- Hackers Use Compromised Azure Credentials to Steal Millions of Enterprise Employee Records cyberpress.org
- McDonald's, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records CyberSecurityNews
Reading Insights
1
6
5 min
vs 6 min read
92%
1,064 → 90 words
Want the full story? Read the original article
Read on InfoStealers