Azure Credential Theft Campaign Hits McDonald’s, Vodafone

Azure credential theft campaign exposes enterprise directories, hits Vodafone and other majors

An Azure credential theft campaign has exposed millions of records from major enterprises, with McDonald’s and Vodafone among the most high-profile victims. The campaign, first revealed on criminal forums in early August 2026, involves a threat actor selling what appear to be internal Microsoft Entra ID (formerly Azure Active Directory) directory exports from at least nine global organisations.

How the Azure Credential Theft Campaign Unfolded

The campaign centres on a seller using the alias “TheHatman,” who has actively advertised directory data from companies including McDonald’s, Vodafone, Tata Consultancy Services (TCS), HCLTech, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware, and Wyndham. Listings began appearing on underground forums on 7 August 2026, with samples of directory exports offered for sale. The largest dataset reportedly belongs to McDonald’s, with over 1.7 million records, while Vodafone’s dump includes approximately 425,000 entries.

  • McDonald’s: 1.7 million records
  • Tata Consultancy Services: 800,000 records
  • Vodafone: 425,000 records
  • HCLTech: 250,000 records
  • IHG: 185,000 records
  • Kyndryl: 170,000 records
  • Gap Inc.: 80,000 records
  • Hexaware: 20,000 records
  • Wyndham: 9,000 records

Researchers at Hudson Rock independently reviewed samples and confirmed they closely match the structure of Microsoft Entra ID directory exports. The data includes full names, corporate email addresses, phone numbers, job titles, departments, reporting lines, and in some cases, mappings of privileged roles and service accounts. These details are typical of what can be retrieved via Microsoft Graph API queries or exported directly from the Entra admin centre.

Technical Analysis: Methods and Exploitation

TheHatman claims all data was obtained using compromised credentials. There is no evidence of an Azure or Entra platform vulnerability. Instead, the attack exploits weaknesses in identity controls and permissions. Once an attacker authenticates using stolen credentials, they can use Microsoft Graph APIs such as /users and /users/{id}/manager endpoints to enumerate users, groups, and relationships. The permissions required for this, such as Directory.Read.All or the Directory Readers role, can be granted to users or applications with over-permissive OAuth consent.

Researchers suspect initial access was gained through infostealer malware, phishing, or weak multi-factor authentication (MFA) enforcement. For example, if an attacker harvests a valid session token or password and MFA controls are weak or missing, they can log in and perform bulk directory exports. The consistency and speed of the dumps suggest an automated process once access was established.

Microsoft has previously documented this attack pattern: threat actors compromise a single identity, escalate privileges or abuse broad app permissions, and then exfiltrate tenant-wide directory information using legitimate APIs. No software patch is relevant, as the activity relies on authenticated use of standard cloud features.

Timeline of the Campaign

  • 7 August 2026: HCLTech directory dump listing appears, with a 7,500-row sample. The full set purportedly exceeds 250,000 records.
  • 11 August 2026: TCS investigates breach claims, finds no evidence of a current compromise, and states data appears to be over four years old.
  • 16 August 2026: CyberSecurityNews reports on the campaign, naming affected companies and confirming the use of compromised credentials.
  • 16 August 2026: McDonald’s data sample of 8,000 rows reviewed by a third party, confirming consistency with Entra directory exports.

As of mid-August 2026, no technical indicators of compromise (IoCs) such as IP addresses, file hashes, or domains have been published. The records on sale are based on credible samples, but most affected companies have not confirmed breaches. TCS has publicly stated any referenced data is historical and limited in sensitivity.

Impact on Enterprises and Potential Risks

The exposure of internal directory data poses multiple risks. Access to names, emails, phone numbers, reporting lines, and privileged roles enables sophisticated social engineering and spear-phishing. For example, attackers can impersonate executives, target IT admins, or map the internal structure for further attacks. The presence of service account and Global Administrator mappings is especially dangerous, as it could guide privilege escalation attempts.

The event demonstrates the risk of identity compromise in cloud environments. Attackers do not need to exploit a vulnerability if they can authenticate as a legitimate user or application with wide-reaching permissions. Over-permissive OAuth grants, lack of phishing-resistant MFA, and insufficient monitoring of cloud API activity all contribute to the scale of the breach.

What Organisations Should Do Next

There is no product patch to apply for this campaign, as it is not based on a software flaw. Microsoft recommends the following specific actions for tenants:

  • Enforce phishing-resistant MFA for all users, especially administrators and sensitive roles.
  • Audit OAuth app consents and remove unnecessary or over-permissive permissions, especially Directory.Read.All.
  • Monitor Microsoft Graph API usage for unusual directory enumeration or export patterns.
  • Review sign-in and audit logs for signs of credential misuse or suspicious activity.

UK organisations using Microsoft 365 or Entra ID should assume that some credentials may be exposed over time and proactively harden identity controls. The data types sold in this campaign are exactly those used in business email compromise and targeted phishing against UK firms.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call