Back to Blog
by 1015058pwpadmin

Massive Azure Data Theft: Why Your Tenant Default Settings Are a Security Risk

Microsoft Azure logo on a dark blue background with the headline Securing Your Azure Tenant

Over the past week, a threat actor known as TheHatman began flooding cybercrime forums with something that should worry every business running Microsoft 365 or Azure: complete internal employee directories pulled straight out of corporate Azure and Entra tenants.

The list of victims reads like a Fortune 500 roster. McDonald’s (more than 1.7 million records), Tata Consultancy Services (800,000 plus), Vodafone (425,000 plus), HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, and others. The data looks legitimate, with corporate email addresses and field names that match standard Azure directory exports exactly.

Here is the part that matters for your business. Researchers found no zero-day and no exotic exploit. The attacker got in with valid, stolen credentials, most likely harvested by infostealer malware on employee machines. From there, permissive tenant defaults did the rest.

What was actually stolen, and why it is dangerous

These were not just name-and-email lists. The exported directories included:

  • Full names, corporate email addresses, phone numbers, and physical addresses
  • Employee IDs, job titles, departments, manager names, and direct reports
  • Group memberships, service accounts, and Global Administrator listings

That last line is the real problem. When an attacker can see your entire org chart plus the names of your service accounts and global admins, they have a precise roadmap. It powers convincing business email compromise, spear-phishing that impersonates a real manager, and targeted attacks on your highest-privilege accounts. One stolen password becomes a blueprint for the next intrusion.

The quiet culprit: Azure tenant defaults

Microsoft builds Azure and Entra to work out of the box, not to be locked down out of the box. Those default settings favor openness and convenience, and most organizations never revisit them. That is exactly what let a single compromised account walk out with an entire company’s directory.

The defaults that create the most risk:

  • Every user can read the entire directory. By default, any authenticated member can enumerate all users, groups, and memberships in the tenant. Compromise one low-level account and you can pull the whole org.
  • MFA is not universally enforced. Many older tenants still allow sign-ins without multi-factor authentication, and legacy authentication protocols that bypass MFA entirely are often still enabled.
  • Guest access is permissive. Default external collaboration settings let guests see more than most businesses realize.
  • Standing global admin access. Tenants routinely carry far too many permanent Global Administrators, each one a high-value target.
  • Long-lived session tokens. Default token lifetimes give a stolen session token a long window of use, which is exactly what infostealers grab.

None of these are bugs. They are defaults. And they are configurable.

Why configuring your defaults is the whole game

The attackers in this campaign did not beat Microsoft’s security. They walked through doors that were left on their factory settings. Hardening your tenant defaults shrinks the blast radius so that one stolen credential no longer equals a full-directory breach.

Concretely, a properly configured tenant:

  • Restricts default user permissions so members cannot enumerate the full directory
  • Enforces phishing-resistant multi-factor authentication through Conditional Access, and disables legacy authentication
  • Locks down guest and external collaboration settings to least privilege
  • Removes standing Global Administrator rights in favor of just-in-time, time-limited elevation
  • Shortens token lifetimes and enables token protection and sign-in risk policies
  • Monitors for credentials that show up in infostealer and dark web data before attackers use them

If you want the deeper technical background on one of these, we covered token lifetimes in our earlier post on Microsoft Entra Configurable Token Lifetimes.

How Nebulara Tech helps

Most small and mid-sized businesses are running the same Azure and Entra defaults as the enterprises in this breach, just without a security team to catch it. That is where we come in.

Nebulara Tech runs an Azure and Entra tenant security assessment that maps your current configuration against these exact risks, then hardens it: directory enumeration locked down, phishing-resistant MFA and Conditional Access rolled out, legacy auth disabled, admin roles right-sized with just-in-time access, and continuous monitoring for compromised credentials. For our healthcare and construction clients across South Florida, we align the whole thing with the compliance obligations you already carry, including HIPAA.

The organizations in the headlines had big budgets and still got caught by their defaults. You do not have to. If you are not sure how your Azure tenant is configured, that uncertainty is the risk. Talk to Nebulara Tech and we will help you find out and fix it.

Published on August 16, 2026
Share on LinkedIn

Ready to Automate Your Business?

Talk to one of our Miami-based consultants. No commitment, no pressure.

Get a Free Consultation Call (407) 279-0728