Skip to content
Azure credential theft puts 3.6 million enterprise directory records up for sale

Azure credential theft puts 3.6 million enterprise directory records up for sale

Feeds.4Sysops IT News August 17, 2026

A threat actor known as TheHatman is advertising roughly 3.6 million employee directory records allegedly stolen from nine Microsoft Azure and Entra ID tenants, including McDonald’s, Tata Consultancy Services, Vodafone, and Kyndryl. Samples appear highly likely to be genuine and reportedly include organizational data that could help attackers identify privileged accounts and target follow-on phishing campaigns. Source

Extracted Entities