azure3 articles
Threat Actor Claims Millions of Corporate Records Lifted from Azure Tenants
A threat actor called "TheHatman" is claiming to have stolen millions of employee records from the Microsoft Azure environments of major corporations including McDonald's, Vodafone, Tata Consultancy Services, and Kyndryl, with the data reportedly including sensitive details such as employee IDs, job titles, and accounts with Global Administrator privileges. Security firm Hudson Rock assessed the data as "highly likely authentic" but could not determine the exact method of access, suggesting possibilities such as infostealer malware, phishing, or weak multi-factor authentication. Tata Consultancy Services has denied finding credible evidence of a breach, stating the referenced information appears to be over four years old and limited to basic employee data.
Hacker Flogs Azure Directory Data From McDonald's, Vodafone and a Stack of Fortune 500 Names
A threat actor known as 'TheHatman' is selling data allegedly stolen from the Azure tenants of multiple Fortune 500 companies, including McDonald's, TCS, Vodafone, and Wyndham Hotels, with the McDonald's dataset alone containing over 1.7 million records. The data, which appears to have been exfiltrated using leaked credentials from a targeted infostealer campaign, includes sensitive employee information such as names, email addresses, job titles, and privileged account details. Security firm Hudson Rock warns the breach poses a serious risk, as the exposed data could enable attackers to conduct spear-phishing, business email compromise, and privilege escalation attacks against the affected organisations.
Accenture Breached: Hacker Claims 35GB Haul Including Source Code and Azure Keys
Accenture has confirmed a data breach after a hacker claimed on PwnForums to have stolen 35 gigabytes of data, including source code, Azure access keys, RSA/SSH keys, and configuration files from the company. Accenture stated the incident has been remediated and that there is no impact on its operations, though it provided few further details. Security experts warn the stolen data could be leveraged for future attacks, given Accenture's close proximity to major enterprise clients' systems and infrastructure.