Jessica Entwistle
August 17 2026
SecurityWeek reports that a threat actor is claiming to have exfiltrated millions of records from multiple large organisations, including McDonald's, Tata Consultancy Services (TCS), and Vodafone, as part of a coordinated campaign targeting Microsoft Azure environments. The attacker has published sample datasets and is offering access to stolen data, which is said to include customer records, internal documents, and operational information. The campaign appears to focus on organisations with significant Azure footprints, exploiting misconfigurations or compromised credentials to gain access to cloud-hosted data stores.
Azure is widely used across UK businesses, and this incident highlights the operational importance of cloud security hygiene, particularly around identity governance, privileged access management, and monitoring for unusual data access patterns. The risk of misconfigured permissions, overly permissive service accounts, or compromised credentials remains a common pathway for attackers seeking to exfiltrate data from cloud environments. The incident also underscores the value of logging and alerting on bulk data access or unusual export activity, which can provide early warning of potential exfiltration. For organisations using Azure, this is a reminder that cloud security is not just about perimeter defence, but about ensuring that access controls are appropriately scoped, that privileged accounts are protected, and that monitoring is in place to detect anomalous activity.
UK organisations using Azure should review cloud identity and access governance, ensuring that privileged accounts are protected with multi-factor authentication and that permissions are scoped according to the principle of least privilege. Review whether logging is configured to detect unusual data access patterns, bulk data exports, or access from unexpected locations or devices. Consider whether monitoring and alerting is in place to detect anomalous activity in cloud environments, and whether incident response processes are prepared to investigate and contain potential data exfiltration. Ensure that ownership of cloud security governance is clear, and that regular reviews of access controls, permissions, and monitoring configurations are part of routine security practice.
Source: SecurityWeek