Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials
Hackers are using compromised credentials to exfiltrate millions of employee records from Azure directories. The campaign targets global enterprises, including Vodafone, McDonald's, TCS, HCL, and Hexaware. Attackers utilize infostealers to acquire the credentials necessary to access these corporate directories. While the total volume of stolen data across all targets remains unspecified, the scale is described as massive, affecting multiple high-profile organizations across different sectors.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ Hackers used compromised Azure credentials to steal millions of enterprise employee records.
- ✓ The data leak is linked to the use of infostealers.
- ✓ McDonald's and Vodafone were hit by the credential theft campaign.
What changed
Reports now identify Vodafone, TCS, HCL, and Hexaware as additional victims of the Azure exfiltration campaign.
Live updates
-
Azure Credential Theft Exposes Millions of Enterprise Records
Hackers are using compromised credentials to exfiltrate millions of employee records from Azure directories. The campaign targets global enterprises, including Vodafone, McDonald's, TCS, HCL, and Hexaware. Attackers utilize infostealers to acquire the credentials necessary to access these corporate directories. While the total volume of stolen data across all targets remains unspecified, the scale is described as massive, affecting multiple high-profile organizations across different sectors.
Why it matters
Azure directories often serve as the central identity hub for enterprise permissions and employee data. Compromising these credentials allows attackers to bypass perimeter security and access sensitive internal records. The use of infostealers indicates a shift toward targeting end-user devices to gain administrative or privileged access.
What is confirmed
- Hackers used compromised Azure credentials to steal millions of enterprise employee records.
- The data leak is linked to the use of infostealers.
- McDonald's and Vodafone were hit by the credential theft campaign.
Still unconfirmed
- A seller claims 1.7 million McDonald's employee records were stolen.
- TCS, HCL, and Hexaware were named in the global Azure directory data leak.
What to watch next
- Confirmation of the exact number of records stolen from McDonald's and Vodafone.
- Statements from TCS, HCL, or Hexaware regarding the breach of their Azure directories.
- Technical analysis of the specific infostealer strains used to capture the credentials.
confidence 85%Sources used for this update (5)
- InfoStealers — Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials
- Security Affairs — McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
- CRN Asia — TCS, HCL, Hexaware named in global Azure directory data leak linked to infostealers
- cyberpress.org — Hackers Use Compromised Azure Credentials to Steal Millions of Enterprise Employee Records
- CyberSecurityNews — McDonald's, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community