Hackers Use Compromised Azure Credentials to Steal Millions of Enterprise Employee Records
Brief
A large-scale Azure data exfiltration campaign is unfolding across underground forums, where a threat actor using the alias “TheHatman” is allegedly selling internal employee directories taken from major multinational organizations.
The actor claims the data was extracted from compromised Microsoft Azure and Entra ID tenants using stolen corporate credentials, exposing a serious identity-security risk for enterprises reliant on cloud directory services.
The listings reportedly cover at least nine Fortune 500-scale companies in technology services, hospitality, telecommunications, retail, and logistics. McDonald’s Corporation is said to account for the largest dataset, containing more than 1. 7 million employee records.
