19/08/2026
✨🌐There are preliminary reports that a threat actor known as TheHatman is selling data allegedly stolen from the Azure and Microsoft Entra ID environments of several Fortune 500-level organizations, including McDonald’s, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, and InterContinental Hotels Group (IHG). The datasets reportedly contain millions of employee directory records, including names, corporate email addresses, phone numbers, employee IDs, job titles, service accounts, and privileged administrator information. The largest dataset reportedly belongs to McDonald’s, with more than 1.7 million records.
According to Hudson Rock, the attacker allegedly obtained the data using previously leaked credentials, potentially linked to targeted infostealer malware campaigns. Exposure of internal organizational structures and privileged accounts could facilitate social engineering, spear-phishing, and Business Email Compromise (BEC) attacks.
Organizations using Azure and Microsoft Entra ID should review logs for suspicious data access, enforce MFA, reset credentials for high-risk accounts, particularly administrators, and raise employee awareness of suspicious emails and communications.
👑Read more : https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/