Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others) | InfoStealers

August 16, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: infostealers.com

Threat Risk: High
Victim: Fortune 500 Enterprises
Incident: Mass exfiltration of employee directory data from Azure Tenants.
Impact: Exposure of millions of employee records and highly privileged account mappings.
Attacker: TheHatman
Analysis: The threat actor ‘TheHatman’ is selling datasets extracted from Azure/Entra portals using compromised credentials. The leak is particularly dangerous because it includes global administrator lists and service account details. This level of visibility allows attackers to map organizational hierarchies and target high-value users for precision spear-phishing.
Recommendations: Enforce phishing-resistant MFA for all Azure/Entra portal access; Audit and rotate credentials for all Global Administrator and service accounts; Monitor for anomalous login patterns and session token theft
Source: InfoStealers / Hudson Rock

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *