# Massive Azure Credential Breach Puts Major Corporations at Risk

*Published August 17, 2026*
*Source: [https://cybersecuritynews.com/azure-credential-theft-campaign/](https://cybersecuritynews.com/azure-credential-theft-campaign/)*

## Executive Summary

An extensive breach of Azure and Entra credentials has led to the sale of internal employee directories from major corporations on the dark web. This incident highlights the critical need for improved credential management and comprehensive security measures to prevent further exploitation.

## Article

A significant security breach involving Azure and Entra credentials has surfaced on the dark web. A threat actor known as 'TheHatman' is reportedly selling internal employee directories from some of the largest corporations globally. These directories were allegedly accessed using compromised credentials, leading to a substantial amount of data being offered for sale.

In the past week, listings have appeared for nine major companies, including McDonald’s Corporation with over 1.7 million records exposed. Other affected companies include Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. Each of these organizations has suffered exposure of hundreds of thousands of records.

Hudson Rock researchers have confirmed the authenticity of these datasets, noting the inclusion of full names, corporate email addresses, phone numbers, and physical addresses. The data further exposes organizational details such as employee IDs, job titles, and even Global Administrator accounts, which poses a significant risk for targeted attacks like spear-phishing and social engineering.

The exact method of intrusion remains unclear, although compromised credentials have been cited as a likely avenue. Potential vectors include infostealer malware, phishing campaigns for administrative access, insufficient multi-factor authentication, or vulnerabilities in third-party integrations. Hudson Rock's findings support the infostealer hypothesis, linking compromised Azure credentials to infostealer infections across various affected companies.

This breach underscores the importance of credential management. Organizations face significant risks from structured data leaks, which can be weaponized in business email compromises and ransomware attacks. The exposure of privileged accounts highlights the necessity for robust security measures beyond traditional perimeter defenses. Companies must prioritize monitoring for compromised credentials, enforce MFA, and scrutinize third-party API permissions to mitigate these risks.
