An alleged campaign linked to TheHatman is reportedly offering Azure/Entra ID directory dumps containing huge numbers of employee records, including a claimed 1.7M+ records from McDonald’s and 800K+ from TCS.
Stolen credentials, session tokens and overprivileged APIs can potentially give attackers access to entire corporate directories.
The leaked data reportedly includes employee identities, job titles, departments, reporting relationships, service accounts and privileged account information, creating a powerful roadmap for phishing, BEC and more.
