If you use customer1.mycorp.com, customer2.mycorp.com, etc. the names of your clients is exposed twice :
- if you issue one certificate with all the domains, all the domains are readable in the certificate (Cloudflare free cert. has this issue too)
- all the LE certificates are published in Certificate Transparency logs. So you can detect if anyone issues a cert. for your domain, but anyone can view the certificates you issued.
With a wildcard certificate, the subdomains used are not public.
Note this issue applies to "internal" subdomains too. You probably don't want to expose the hostname of your backoffice (admin.mycorp.com) or your new top secret project (linux.microsoft.org).