Microsoft Azure is the enterprise cloud platform that large companies rent. Four outlets trace the alleged haul to compromised customer credentials, not a flaw in Microsoft itself.
A criminal is advertising millions of records allegedly stolen from Microsoft Azure corporate cloud customers, claiming the data came from compromised customer credentials, not a flaw in Microsoft's own infrastructure.
The Register reported the sales post on Monday, using the term "allegedly plundered" for the corporate Azure tenants, Microsoft's word for the segregated cloud accounts large companies and governments rent on the platform. The seller's asking price and exact record count have not been publicly verified.
Three other outlets converged on the same campaign this week. SecurityWeek headlines the incident as a Fortune 500 data-theft campaign. CyberPress and InfoStealers both point to compromised Azure credentials as the access vector, with InfoStealers naming McDonald's, Vodafone, and Kyndryl.
Sellers on criminal forums routinely overstate inventory and provenance, and none of the four outlets report a Microsoft-side investigation or a confirmed tenant compromise. Actual haul size, record types, and full victim list remain unverified.
When an attacker steals an employee's cloud sign-in, typically via an infostealer log rather than a Microsoft vulnerability, every dataset that employee can read becomes a candidate for exfiltration. For any company running in Azure, the control that failed is customer-side credential hygiene, not the platform.