A threat actor using the alias "TheHatman" conducted a large-scale credential-theft campaign targeting Microsoft Azure and Entra ID tenants, exfiltrating millions of corporate employee directory records from major multinational organizations including McDonald's (1.7M+ records), Vodafone (425K+), Tata Consultancy Services (800K+), and others. The stolen data includes display names, employee IDs, corporate emails, user principal names, phone numbers, job titles, department structures, manager relationships, and references to privileged accounts. Attackers obtained access via compromised credentials from infostealer malware, weak authentication, or phishing; the data enables high-precision spear-phishing, business email compromise, and targeted credential harvesting attacks.
// Alert
Microsoft Azure threat report
// Get alerts for Microsoft Azure