Just came across an interesting report from Hudson Rock. A threat actor claims to have extracted millions of enterprise records from Azure tenants.
Some of the organizations reportedly affected:
- McDonald’s: ~1.7M+ records
- TCS: ~800K+
- Vodafone: ~425K+
- HCL Technologies: ~250K+
- IHG: ~185K+
- Kyndryl: ~170K+
- Gap: ~80K+
- Hexaware: ~20K+
- Wyndham Hotels: ~9K+
The exact attack vector is not yet confirmed, but compromised credentials, stolen session tokens, phishing or overly permissive integrations are among the possibilities.
Another reminder of how important identity security is in cloud environments.
Worth a read 👇