// Microsoft 365HIGH
A threat actor known as 'TheHatman' claims to have stolen millions of employee records from Azure/Entra ID directories of at least nine Fortune 500 companies, including McDonald's (1.7M records), TCS (~800K), Vodafone (~425K), and others. The exposed data includes full names, corporate emails, job titles, manager chains, and Global Administrator account listings, likely obtained through infostealer-compromised credentials. Researchers assess the data as highly credible and note the stolen org charts are ideal for spear-phishing and business email compromise attacks.
- Week in review: Records allegedly stolen from Azure tenants, Med(opens in a new tab)
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude(opens in a new tab)
// Get alerts for Microsoft 365