Fortune 500 Companies Hit in Azure Data Theft Campaign (opens in a new tab)
Why readTells you which named enterprises had Entra directory exports pulled with leaked credentials, and how many records each dump holds, so you can judge your own exposure or a supplier's.
An actor going by TheHatman is advertising employee directory data said to come straight from the Azure and Entra tenants of McDonald's, TCS, Vodafone, HCL, IHG, Kyndryl, Gap, Hexaware and Wyndham, with the McDonald's set alone at over 1.7 million records. Hudson Rock reports the field names and email formats line up with genuine Azure directory exports, and the stated access route is simply stolen credentials rather than any product flaw. Nothing here is confirmed by the named companies, but three of the listed victims are large IT outsourcers, which makes the directory data useful raw material for targeted phishing against their clients.
Also covered byThe Register Security (opens in a new tab),SQ Magazine (opens in a new tab).