Threat actor claims Azure and Entra data theft from McDonald’s, TCS, Vodafone, and other major companies

A threat actor is offering data allegedly stolen from the Azure and Microsoft Entra environments of several major companies, including McDonald’s, TCS, Vodafone, HCL, IHG, Kyndryl, Gap, Hexaware, and Wyndham. SecurityWeek, citing Hudson Rock, says the dumps appear to contain legitimate Azure directory export data such as employee names, corporate emails, phone numbers, job titles, manager relationships, group memberships, service accounts, and privileged account records. The claimed access vector is leaked credentials, likely obtained through infostealer malware, but no CVE is cited.
Why it matters: If authentic, the stolen directory data gives attackers a detailed map of internal staff, admins, and service accounts that can fuel highly convincing phishing, business email compromise, and follow-on intrusions. Organizations using Microsoft Entra and Azure should urgently investigate credential theft, review admin exposure, rotate compromised accounts, and watch for targeted social-engineering attempts.

Sources

Hacker claims 3.6 million Azure account records stolen from major companies
Ionut Ilascu 2026.08.17 98% relevant
This is a direct update on the same claimed multi-company Azure/Entra data-theft event, adding the actor alias TheHatman, the claimed total of 3.64 million records, a victim list including McDonald’s, Gap, Vodafone, TCS, HCL, IHG, Wyndham, Hexaware, and Kyndryl, sample-data details, Hudson Rock’s assessment of the dumps, and denials or partial characterizations from TCS and Gap.
Crook hawks millions of records allegedly plundered from corporate Azure tenants
2026.08.17 96% relevant
This article is a direct follow-up on the same alleged Azure/Entra tenant data-theft incident, adding The Register's reporting, the list of nine named organizations, the claimed record counts per company, Hudson Rock's assessment that the samples look authentic, and TCS's public response disputing a current breach.
Fortune 500 Companies Hit in Azure Data Theft Campaign
Ionut Arghire 2026.08.17 100% relevant
This article appears to be the first cited report of a distinct multi-victim campaign in which a threat actor claims to have exfiltrated corporate directory data directly from Azure/Entra tenants using stolen credentials.
← Back to all stories