Cloud identity has become one of the most valuable targets for attackers. A single compromised credential can provide access to enterprise directories, cloud resources, employee information, and privileged accounts without requiring attackers to exploit a vulnerability in the underlying cloud platform.
According to Cybersecurity News, a sprawling Azure credential theft campaign is exposing millions of enterprise records from major organizations. The campaign involves a threat actor operating under the alias “TheHatman,” who claims to have obtained the data from compromised Azure and Entra tenants using stolen credentials.
The reported victims include major organizations across multiple industries, with McDonald’s reportedly having more than 1.7 million exposed records, Tata Consultancy Services around 800,000, Vodafone approximately 425,000, and HCL Technologies around 250,000. Additional organizations named in the report include InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.
The stolen datasets reportedly contain much more than basic employee contact information.
According to the report, the datasets include:
The exposure of organizational relationships and privileged account information makes the campaign particularly concerning.
Attackers can use this information to build highly targeted spear-phishing and social engineering campaigns. Knowing who manages whom, which employees hold administrative roles, and which service accounts exist gives attackers a detailed map of the organization’s identity environment.

The precise initial access method has not been confirmed.
The threat actor claims the information was obtained using compromised credentials, while researchers identified several possible explanations for how those credentials may have been obtained.
One possible route involves infostealer malware infecting employee systems and harvesting credentials and session information.
Researchers reportedly identified compromised Azure credentials associated with infostealer infections linked to employees at several affected organizations, including TCS, Gap Inc., HCL Technologies, and Kyndryl.
One compromised device reportedly contained dozens of corporate credentials and hundreds of sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account.
Another possible entry point is phishing.
Attackers can use convincing corporate impersonation campaigns to obtain employee credentials or privileged account access. Once valid credentials are obtained, the attacker can authenticate to cloud environments using legitimate access rather than exploiting an obvious software vulnerability.
The report also identifies insufficient Multi-Factor Authentication enforcement as another possible explanation.
If privileged Azure and Entra accounts are not adequately protected with strong authentication controls, stolen credentials can provide attackers with direct access to cloud resources.
Another possibility is abuse of a third-party API or integration with excessively broad read permissions.
An overly permissive integration can provide attackers with access to large volumes of directory information once the associated credential or token is compromised.
The scale of the reported campaign suggests that the attackers were not manually collecting information from individual accounts.
Once access to an Azure or Entra tenant was established, the attackers appear to have systematically collected structured directory information.
This included organizational relationships, account information, service accounts, and privileged identities.
That creates a multiplier effect.
One compromised identity can potentially expose information about thousands of other employees and accounts, providing attackers with additional targets for future attacks.
The reported exposure of Global Administrator account information creates an additional risk.
An attacker does not necessarily need to compromise a Global Administrator immediately.
Knowing which accounts hold privileged roles can help attackers prioritize their targeting.
They can use accurate organizational information to create highly convincing:
The directory information effectively becomes a targeting map for future attacks.
The stolen information can potentially be used long after the original Azure compromise.
Attackers can combine employee information with other stolen credentials and session data to create more convincing attacks.
For example, knowing an employee’s:
can make a fraudulent request appear far more legitimate.
This means the campaign can potentially become the starting point for additional account compromise, business email compromise, and targeted social engineering.
The campaign reinforces several defensive priorities.
Organizations should continuously monitor for credentials exposed through infostealer infections and immediately investigate accounts associated with compromised devices.
Strong MFA should be enforced across Azure and Entra environments, particularly for privileged accounts.
Organizations should also review third-party integrations and API permissions to ensure that applications are not receiving broader access to directory information than they actually require.
Cloud identity monitoring should extend beyond successful and failed logins. Security teams need to understand what authenticated users and applications do after access is granted.
This attack is primarily an identity and cloud access compromise, so the most relevant Seceon capabilities are behavioral detection and cross-environment correlation.
Seceon’s aiSIEM / CGuard provides centralized visibility across identity, endpoint, network, and cloud activity.
For an Azure credential theft campaign, it can help organizations:
The SIEM’s behavioral analytics capability is particularly important because attackers using stolen credentials may appear legitimate at the authentication layer.
The important question becomes not simply “Was the login successful?”, but “Is this behavior consistent with how this identity normally operates?”
If stolen Azure credentials originate from an infostealer-compromised endpoint, aiXDR-PMax can help detect the activity occurring on that endpoint.
Relevant detection includes:
This creates an important connection between the endpoint and cloud sides of the attack.
Instead of treating an Azure login and an infected employee machine as two unrelated events, Seceon can correlate them as part of the same potential attack chain.
aiSecurityScore360 can help organizations understand their broader external exposure and identify security weaknesses that may increase the likelihood of successful compromise.
For organizations concerned about cloud identity exposure, maintaining visibility into externally exposed assets and security weaknesses provides an additional layer of risk assessment alongside continuous detection.
aiBAS360 can be used to validate whether security controls are capable of detecting identity-focused attack scenarios.
Organizations can use controlled security validation to test scenarios involving:
This helps security teams determine whether their defenses can detect the attack chain rather than simply relying on preventive controls.

The Azure credential theft campaign demonstrates how compromised credentials can become more dangerous than a conventional vulnerability.
The attackers reportedly obtained structured information from Azure and Entra environments containing millions of employee records, organizational relationships, service account information, and privileged account details.
The exact initial access method remains unconfirmed, but the reported connection between infostealer-compromised devices and Azure credentials highlights an important security reality.
Cloud identity security cannot stop at authentication.
Organizations need continuous visibility across endpoints, identities, cloud activity, and user behavior to identify when legitimate credentials are being used illegitimately.
A stolen credential may give an attacker the first step. Behavioral detection and cross-environment correlation can help prevent that first step from becoming an enterprise-wide compromise.
