← Back to feed
DFIREmerging1 sourceAug 17, 2026 · 10:16via AboutDFIR

Infosec News Nuggets — August 17, 2026

Brief

McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records

A threat actor going by “TheHatman” has been flooding underground forums with employee directory data pulled from at least nine major corporations’ Azure and Entra tenants using compromised credentials, with McDonald’s alone accounting for more than 1. 7 million exposed records alongside troves from Vodafone, Tata Consultancy Services, and other multinationals.

Researchers say infostealer-harvested session tokens appear to be the likely entry point, and the leaked data includes job titles, reporting lines, and administrator account details that could fuel convincing spear-phishing and business email compromise campaigns.

Read more on AboutDFIR