# Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials

> **Open Intelligence Dossier** · First detected: 2026-08-17 11:07 UTC · Category: Business

## Executive Summary
A massive Azure exfiltration campaign has exposed millions of enterprise records, targeting major global brands through compromised credentials.

## Intelligence Brief
A wide-scale data exfiltration campaign targeting Microsoft Azure has resulted in the exposure of millions of enterprise employee records. According to reports from CyberSecurityNews and cyberpress.org, the breach was facilitated by the use of compromised Azure credentials to gain unauthorized access to corporate environments. The scale of the theft is significant, affecting a diverse range of global organizations across multiple sectors. Specific companies identified as victims of the campaign include McDonald&amp;#039;s and Vodafone, both of whom were hit by the credential theft operation that led to the exposure of sensitive enterprise data. Detailed coverage from several outlets highlights the specific targets and the nature of the data loss. Security Affairs reports that employee data from McDonald&amp;#039;s has appeared in a leak, with a seller claiming that 1.7 million records were stolen from the company.


Furthermore, crnasia.com identifies several major IT services and consulting firms as being involved in the breach. These include TCS, HCL, and Hexaware, which were named in a global Azure directory data leak. The reporting across these outlets emphasizes that the campaign focused on extracting directory data and employee information from large-scale enterprise environments. Context provided by InfoStealers and crnasia.com indicates that the campaign is closely linked to the use of infostealers. These malicious software tools are designed to harvest credentials from infected devices, which the hackers then utilized to bypass security and enter Azure environments. The focus on Azure directory data suggests a systemic vulnerability regarding how enterprise credentials are managed and stolen.


This event matters now because it demonstrates the ability of attackers to target high-profile global corporations like Vodafone and McDonald&amp;#039;s simultaneously using automated credential theft methods. Future developments to watch involve the verification of the claims made by the data sellers regarding the volume of stolen records. While Security Affairs notes a claim of 1.7 million records for McDonald&amp;#039;s, the total number of records across all affected companies remains described generally as millions. Observers will likely monitor if further companies are named alongside TCS, HCL, and Hexaware as the global Azure directory leak is further analyzed. Coverage does not yet specify the exact number of total compromised accounts or the specific types of employee data beyond the general category of enterprise records.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| CyberSecurityNews | McDonald's, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records | [Source Link](https://news.google.com/rss/articles/CBMib0FVX3lxTE5zLVlhUUl0QjZLODhHUDNZRHB2WHpmY245NEVSU20zS1B0a3BLSmVKMFBVNXdPcl9TY2NoREh3Y0JkY3NKS0ZlQmprMEY3STRUM3VJaHBhNjFZNVhXOFFsS1FwS0lkdjZ1cUpaWkN5Z9IBdEFVX3lxTE5RZlA3bmxrV09DUzh0ZVZzaXROOXRPV0xIQ1E0ZXA5VzJCb1Q5dkZRazQ0cndiU01rdllCbk5qclZQRVo5OF9sRXFmdkJEdmJYVXBYRG1aSURBVE5PNGRqd1dvMTVfTkNlYS1rejloRDNBY1hS?oc=5) |
| cyberpress.org | Hackers Use Compromised Azure Credentials to Steal Millions of Enterprise Employee Records | [Source Link](https://news.google.com/rss/articles/CBMic0FVX3lxTFBWMDZOQ1JJUEJ2MzNPcGJNVTVPT2VwZ0JOdVNPcjlCNDk2eHFXNG83SE9Uc1Qxb2Z5UkpyQTlFVHNFVHhvckFFMGRrZzlmaWF2dFNuZWxYak5iVGNfLWJaU3NaLTdFSno3WldNRU5BcmV2WHfSAXNBVV95cUxQVjA2TkNSSVBCdjMzT3BiTVU1T09lcGdCTnVTT3I5QjQ5NnhxVzRvN0hPVHNUMW9meVJKckE5RVRzRVR4b3JBRTBka2c5ZmlhdnRTbmVsWGpOYlRjXy1iWlNzWi03RUp6N1pXTUVOQXJldlh3?oc=5) |
| crnasia.com | TCS, HCL, Hexaware named in global Azure directory data leak linked to infostealers | [Source Link](https://news.google.com/rss/articles/CBMivgFBVV95cUxNc0dsdlVfaFBCdUl4OHNXR1dyQWlOVlRadnJlczJjUzBOa2FkbEY1aG8wVGw3cW5SXzBrbUVPVG84VTZyMVBxYnRlRGNhc3gzQ2dWUlNSLXdFLXJZQjRlR0lONEVJSElPMUlaM0lQajQyWlhSc1ZaWWRhTmU1aGtreXlVVnZPT2FwZ3FRaktEbDJUa2h1Z1JQbXFiSjVBRjMweWtkMDBSejg2RXVEWUlHWHA1cEpuMXhRRnYzTWhR?oc=5) |
| Security Affairs | McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen | [Source Link](https://news.google.com/rss/articles/CBMiwwFBVV95cUxQZ0U1d3RXbm9BaGhJNW5YSHNOODVBUkR0UTdYaC1mcHE0ZTZKTHZXR0h0ZzZESm53OEt4cTJ1b09qWG1IM18yeFpUYkFfeFBsTG9FVGNpamp0WVQ0Z3QwUWp1MjR3dS1BcVNlcFJScWJuWXozVUxicnZrYjdoRWo2dGRoaGpvMlZ1dmEyS0c5bHZhVm5iOTlONDBqU2hLZE5iNjNyc1lMaGdTa181Y2lfVzd5ajJDZzJPWlFxY3dibDZMV2fSAcgBQVVfeXFMUHJacS1RMlVlNGdJTk10VjI3dkQyWmM3MmlIZFZveDRkQTZ3MTA1a0JRbWRKdzE1VG1EcjkyZGZZWks2MnFILWszTUtGWVZ3Rk9nMlVGLURXQ1BJMjVHWnhUWE5KUmhzbEZiaERhV2huS2F0UUdvb3Y1WjlsYk1xMGRWRm40V3kxbkJ2T2tIUzd) |
| InfoStealers | Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials | [Source Link](https://news.google.com/rss/articles/CBMihAJBVV95cUxNR2N2b2VzOG1EanZOQ3poYmZGUW1KREpVQ1ZNLVVRYUZpbEVLUWxIQjlhQW5tOElEWXpST2xUMi1aZTlnYWdWTFZnNV9YM3doX0FYd3dUOWhBUmt2aTRsQVY5OXFNRjAxNmt0czdaelhqZjhiRDdoRkR3dmhNVFg0VmZlWWpHWWdybmlmQlhFLUhEbkJfOXJiQnlCUXFmS2taeWE3UjYtTGtXYlVIUWlSdU9Cek1mM2xlQ3hxMzB2SVJvNmVHVGc5VlRGRExKZmFEUkFwem5WRU1Jd2VLbHpHQ2dwQ3RIcEJQLUZXcVotQkVUZnF0eXRrTGI0U1BmbUFDNHhwRg?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-08-17/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via*
