Back Feeds.4Sysops Azure credential theft puts 3.6 million enterprise directory records up for sale
A threat actor known as TheHatman is advertising roughly 3.6 million employee directory records allegedly stolen from nine Microsoft Azure and Entra ID tenants, including McDonald’s, Tata Consultancy Services, Vodafone, and Kyndryl. Samples appear highly likely to be genuine and reportedly include organizational data that could help attackers identify privileged accounts and target follow-on phishing campaigns. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
