McDonald’s, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records
RedSide Security August 16, 2026 Data Leaks & Breaches 14 views
A threat actor known as TheHatman is allegedly selling employee directories stolen from major enterprises through compromised Azure and Microsoft Entra credentials. The campaign reportedly exposes millions of records, including corporate emails, employee details, reporting structures, service accounts, and administrator information, creating significant risks for spear-phishing, privilege escalation, and further network compromise.