Researchers link Vodafone to Azure credential theft and exposed employee phishing risk
Researchers attribute an alleged leak of millions of records from McDonald’s and Vodafone to compromised Azure credentials and infostealer malware, rather than a confirmed Azure zero-day. The stolen data could enable highly convincing phishing and impersonation attacks on employees at large global organizations. Hudson Rock says it found links between infostealer infections and Azure accounts tied to several firms, and says exports look consistent with Microsoft directory services.
Coverage (3)
- Hacker Claims To Have Stolen 3.6 Million Records From McDonald’s, Vodafone and Other Corporate Azure Tenants (linkedin.com)
- Hacker claims to have stolen millions of Azure customer records from McDonald’s, Vodafone, Kyndryl, and others – here's what we know so far (itpro.com)
- Hackers dump millions of records from McDonald’s, Vodafone, and Fortune 500 companies (cybernews.com)