A seller going by “TheHatman” is currently offering underground marketplaces employee data lifted from Microsoft Azure and Entra environments belonging to major firms including McDonald’s, Vodafone, Tata Consultancy Services and Kyndryl. McDonald’s alone has reportedly had over 1.7 million records exposed; Vodafone around 425,000. The data includes names, corporate email addresses, phone numbers, job titles, departments and internal reporting lines.

This isn’t a story about Microsoft’s cloud being breached. Security researchers tracing the campaign have found compromised Azure and Entra credentials originating from infostealer malware infections — the kind that quietly harvests saved passwords, session cookies and login details from an infected device and ships them off to a criminal marketplace. The attacker didn’t break into Azure. They logged in, using stolen credentials someone else obtained months earlier.

That distinction matters enormously if you’re a UK small or mid-sized business running Microsoft 365 or Azure, which most now are in some form. The vulnerability here wasn’t a flaw in Microsoft’s software. It was a password, sitting unprotected on somebody’s laptop, that a piece of malware found and sold on.

Why this should worry smaller businesses, not just household names

It’s tempting to read a story about McDonald’s and Vodafone and assume it’s a big-company problem. It isn’t. Infostealer malware doesn’t target household names specifically — it infects whatever device it can, often via a fake software download, a cracked app, or a malicious browser extension, and then harvests every saved credential it finds, corporate or personal. A firm with 20 staff and a firm with 20,000 are equally exposed if an employee’s laptop gets infected.

What makes this campaign effective is scale and patience. Stolen credentials sit on criminal marketplaces for months before anyone uses them, which is exactly why routine password hygiene often fails to catch the problem — by the time the login is used to break in, the employee has usually forgotten they were ever compromised.

Three checks worth doing this week

Turn on multi-factor authentication everywhere, no exceptions. A stolen password alone is far less useful to an attacker if MFA is enforced on every account with access to Microsoft 365, Azure or Entra. If any admin or service accounts are exempted from MFA “because it’s easier,” that’s the gap to close first.

Check whether your organisation’s domain shows up in a credential-monitoring service. Tools that scan dark web marketplaces and infostealer logs for your company’s email domain can flag a compromised employee credential before it’s used, not after. KeepSafe monitors specifically for this kind of exposure and can tell you if your business’s credentials are already circulating.

Review conditional access and session policies. Even with MFA in place, a stolen active session cookie can sometimes bypass it. If your IT provider hasn’t set up conditional access rules that limit logins to known devices or locations, this is a good week to ask why.

The takeaway

This breach happened because a password was stolen from a device, not because Azure was broken into — which means the fix isn’t waiting for Microsoft to patch something. It’s making sure your own staff’s credentials aren’t the weak link that gets your business added to the next list.