Azure Credential Theft Campaign Exposes Millions of Enterprise Records
A large-scale Azure credential theft campaign has been uncovered, exposing millions of enterprise records from major organizations. The threat actor, known as 'TheHatman,' claims to have obtained the data using compromised Azure and Entra tenants' credentials.
The reported victims include McDonald's (1.7 million exposed records), Vodafone (425,000 records), Tata Consultancy Services (800,000 records), and HCL Technologies (250,000 records). Other affected organizations include InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.
The stolen datasets contain sensitive employee information, including full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager assignments, direct reports, service account information, and Global Administrator account listings. This exposure poses a significant risk as attackers can use this information to launch targeted spear-phishing campaigns and social engineering attacks.