Azure Credential Breach Leaks Millions of Enterprise Directory Records

1 min read
Source: InfoStealers
Azure Credential Breach Leaks Millions of Enterprise Directory Records
Photo: InfoStealers
TL;DR Summary

A threat actor named TheHatman is selling massive Azure/Entra tenant dumps containing employee records from multiple major companies, including McDonald’s (~1.7M) and Vodafone (~425k), exfiltrated via compromised credentials. The data fields cover names, corporate emails, phone numbers, addresses, job titles, departments, and privileged accounts, enabling targeted BEC and privilege escalation. While the exact intrusion vector isn’t confirmed, researchers link the leaks to Infostealer infections and credential abuse rather than a Azure zero-day. Defenders should monitor for credential exposure, enforce MFA, and review third-party access to Azure directories to mitigate risk.}

Share this article

Reading Insights

Total Reads

1

Unique Readers

6

Time Saved

5 min

vs 6 min read

Condensed

92%

1,06490 words

Want the full story? Read the original article

Read on InfoStealers