TechNewsReel
Live

3.6 Million Employee Records from Major Corporations Leaked via Azure

Data from companies including McDonald's and Vodafone was allegedly stolen from Microsoft Azure systems and listed on the dark web.

TechNewsReel Newsroom · August 24, 2026

Millions of corporate employees are facing potential identity theft after a massive cache of personnel data was allegedly stolen from Microsoft Azure systems and listed for sale on the dark web. The breach affects approximately 3.6 million employee records across several major global corporations.

According to reports from CPO Magazine and Digit, the leaked databases include sensitive information from companies such as McDonald's, Gap Inc, Vodafone, and Tata Consultancy Services (TCS). The compromised data allegedly consists of names, email addresses, phone numbers, job titles, and postal addresses. These records are currently being traded or shared within underground forums, exposing a vast network of corporate personnel to targeted attacks.

The Azure Connection

This leak is part of a broader, rising trend where threat actors target large corporate entities to obtain high-value Personally Identifiable Information (PII). While initial reports generalized the targets as Fortune 500 companies, further investigation indicates the data was allegedly stolen from Microsoft Azure tenants. Evidence suggests that compromised credentials may have been used to gain unauthorized access to these specific cloud environments, rather than a systemic vulnerability in a shared HR provider.

Risks to the Workforce

The scale of this breach poses a significant security risk to the affected individuals. High-value PII is frequently used by cybercriminals to launch sophisticated phishing campaigns, commit identity theft, or conduct corporate espionage. By combining job titles with contact information, attackers can craft highly convincing "spear-phishing" emails that appear to come from internal leadership or HR departments, potentially leading to further breaches of corporate networks.

What's Next

Efforts to fully identify every affected company and the exact scope of the data remain ongoing. While the presence of the data on the dark web is confirmed, the specific method of entry for each Azure tenant is still being analyzed. Employees of the mentioned firms are encouraged to monitor their accounts for suspicious activity and remain vigilant against unsolicited communications requesting sensitive information. This incident highlights the critical importance of robust credential management and multi-factor authentication for cloud-based corporate environments to prevent unauthorized access to sensitive personnel databases.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.