Threat Intelligence Brief
Curated summary with source attribution
Source: securityaffairs.com
Threat Risk: Medium
Victim: McDonald’s
Incident: Unauthorized export of employee directory data from a corporate Azure tenant.
Impact: Exposure of PII and account details for approximately 1.7 million employees and contractors globally.
Attacker: TheHatman
Analysis: Threat actors accessed a McDonald’s Azure tenant using compromised credentials to perform a bulk export of user accounts via Entra ID. The leaked data includes service accounts and employee details across more than 30 countries, providing a roadmap for targeted social engineering. Technical indicators, such as specific PowerShell export artifacts, confirm the data’s authenticity.
Recommendations: Enforce phishing-resistant Multi-Factor Authentication (MFA) across all cloud identity providers.; Audit Azure/Entra ID access logs for unauthorized administrative exports or unusual credential usage.; Issue a targeted security awareness alert to employees regarding sophisticated phishing attempts using internal job titles.
Source: Security Affairs
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source