decrypted · 18 august 2026 · vulnerabilities and patching · uk policy and law · surveillance and privacy

The Azure breach that named Vodafone, and the MFA that waved it through

A seller trading as TheHatman has spent the past few days offering employee records lifted from the Microsoft Azure and Entra tenants of nine large companies, Vodafone among them, according to research from Hudson Rock reported by The Register on 17 August. The claimed haul runs to 3.6 million records: roughly 425,000 attributed to Vodafone, 1.7 million to McDonald's, 800,000 to Tata Consultancy Services, and the rest spread across HCL Technologies, IHG, Kyndryl, Gap, Hexaware and Wyndham. Nothing here needed a zero-day. TCS says the attacker claims to have used password spraying backed by MFA fatigue, which describes identity controls doing exactly what they were configured to do, in tenants where that turned out to be not quite enough.

MFA that asks the wrong question

MFA fatigue is a low-skill trick with a high hit rate: fire enough push notifications at a phone at 2am and eventually someone taps approve just to make it stop. It works precisely because the standard "approve this sign-in" prompt asks the user to vouch for an event they had no part in, rather than to prove anything about themselves. Number-matching prompts, and better still hardware-backed passkeys, close that gap by making the approval meaningless without the context only the real user has. Vodafone, McDonald's and most of the other named firms had not responded publicly by the time of writing, so treat the entry method as the attacker's own claim rather than a confirmed fact: Hudson Rock's independent read leans towards credentials harvested by infostealer malware as the more likely route in. Either way, the fix is the same: retire push-only MFA for anything touching a corporate directory.

What a directory export is worth

What TheHatman is actually selling is less dramatic than "millions of records" implies, and more useful to a follow-on attacker than that headline suggests. The data is corporate directory information: names, job titles, phone numbers, manager chains, and, in places, the names of Global Administrator and service accounts. TCS and Gap have both said the data is old and unremarkable, which may well be true. It is also beside the point. An org chart with admin accounts flagged is a targeting list, not a headline breach, and it is worth exactly as much to a phishing operation as a fresher one would be. Secure by Design here means bulk directory reads should not be a standing capability of any authenticated account: Microsoft Graph API permissions and conditional access policies should gate who can enumerate a tenant's full staff list, not just who can log in.

Also this week

The ICO reprimanded ACRO Criminal Records Office on 13 August over a breach that ran from August 2022 to March 2023, after a hacker got into the customer-facing web portal built on Kentico CMS software that had not been patched since 2019, despite multiple public vulnerabilities being disclosed against it in the meantime. Up to 10,920 people had data at risk, including National Insurance numbers, passport details and, for some, biometric and criminal-offence data. The one thing that worked: network segmentation kept the attacker inside the compromised website environment and out of ACRO's core systems, which the ICO explicitly credited with limiting the damage. Patch management failed for four years; the fallback control that should never depend on patching held anyway. That is the pairing worth remembering, not just the failure.

Apple's Screen Sharing feature on macOS carried an authentication bypass, CVE-2026-65400, that let an attacker on the network connect without valid credentials, patched on 6 August across Tahoe, Sequoia and Sonoma. The Dutch national cyber security centre reported active exploitation from 12 August, all of it against Macs with the Screen Sharing port, 5900, reachable directly from the internet; every confirmed case ended with root access and a Monero miner installed. CISA now rates the flaw 9.8 out of 10. Remote-desktop services, VNC included, belong behind a VPN or nothing at all: exposing one to the open internet has been a bad idea since long before this particular bug existed.

Sources

Questions about identity controls or patch governance in your own estate? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.