$ techbeacon
Phishing

Corporate Directories of McDonald's and Vodafone Offered for Sale in Azure Credential Campaign

Corporate Directories of McDonald's and Vodafone Offered for Sale in Azure Credential Campaign

A prominent threat actor operating under the alias "TheHatman" is reportedly selling massive corporate employee directories allegedly stolen from several major global enterprises. Among the primary organizations targeted in the campaign are fast-food giant McDonald's and telecommunications multinational Vodafone. The threat actor claims the data was harvested by exploiting compromised credentials to infiltrate corporate Microsoft Azure and Entra ID environments.

According to security reports, the stolen datasets have been advertised on various cybercrime forums, where they are being offered to the highest bidders. The actor claims to have successfully extracted sensitive internal directory structures, which typically contain employee names, email addresses, phone numbers, department roles, and organizational hierarchies.

The breach highlights critical vulnerabilities in cloud identity management. Microsoft Azure and Entra ID—formerly known as Azure Active Directory—are widely utilized by multinational corporations to manage user identities and control access to corporate networks. By gaining unauthorized access to these tenants through compromised credentials, the attacker was able to bypass traditional perimeter defenses and directly access internal directories.

While employee directories do not typically contain consumer financial details or credit card information, they are highly valuable to cybercriminals. Access to a company's complete directory allows malicious actors to map out corporate structures and launch highly targeted social engineering campaigns. These details are frequently used to execute sophisticated spear-phishing operations and business email compromise (BEC) schemes, which can lead to even deeper network intrusions.

Cybersecurity experts warn that credential-based attacks on cloud infrastructure are becoming increasingly common as enterprises transition more of their operations to the cloud. To mitigate these risks, organizations are urged to enforce strict multi-factor authentication (MFA) protocols, monitor for unusual login locations, and regularly audit privileged accounts that have access to directory services.

The full extent of the data exposure remains under investigation, and the affected corporations have not yet detailed the scope of the compromise. This campaign, initially reported by cybersecurity outlet GBHackers, serves as a stark reminder of the critical importance of securing identity provider platforms against credential theft.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related