Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others)
Brief
Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials
A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials.
Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants.
A screenshot showing the extent of the threat actor’s posts on a dark web forum, listing multiple global enterprises.
