Skip to content
Back to Guavy Wire
Stocks

Azure Credential Theft Campaign Exposes Millions of Enterprise Records

Instruments
MCD
Share

A large-scale Azure credential theft campaign has been uncovered, exposing millions of enterprise records from major organizations. The threat actor, known as 'TheHatman,' claims to have obtained the data using compromised Azure and Entra tenants' credentials.

The reported victims include McDonald's (1.7 million exposed records), Vodafone (425,000 records), Tata Consultancy Services (800,000 records), and HCL Technologies (250,000 records). Other affected organizations include InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.

The stolen datasets contain sensitive employee information, including full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager assignments, direct reports, service account information, and Global Administrator account listings. This exposure poses a significant risk as attackers can use this information to launch targeted spear-phishing campaigns and social engineering attacks.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc