← BACK TO FEED
data breachAzureinfostealercredential theftcybercrime

Threat Actor Claims Millions of Corporate Records Lifted from Azure Tenants

A threat actor called "TheHatman" is claiming to have stolen millions of employee records from the Microsoft Azure environments of major corporations including McDonald's, Vodafone, Tata Consultancy Services, and Kyndryl, with the data reportedly including sensitive details such as employee IDs, job titles, and accounts with Global Administrator privileges. Security firm Hudson Rock assessed the data as "highly likely authentic" but could not determine the exact method of access, suggesting possibilities such as infostealer malware, phishing, or weak multi-factor authentication. Tata Consultancy Services has denied finding credible evidence of a breach, stating the referenced information appears to be over four years old and limited to basic employee data.

A threat actor going by the name 'TheHatman' is flogging what they claim are millions of employee records pulled from the Microsoft Azure environments of some very large companies. McDonald's, Vodafone, Tata Consultancy Services, Kyndryl, HCL Technologies, IHG Hotels & Resorts, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts are all allegedly on the list.

Security firm Hudson Rock broke the story after reviewing samples of the advertised data. Their assessment: 'highly likely authentic.' The records apparently match the structure and formatting you'd expect from Microsoft Azure directory exports, and include corporate email addresses consistent with the named organisations.

McDonald's supposedly accounts for the biggest chunk, with 1.7 million records up for sale. TCS follows at around 800,000, Vodafone at 425,000, and HCL at 250,000. The remaining companies make up the rest of an alleged nine-organisation haul.

This isn't just names and work email addresses, either. The samples reportedly contain phone numbers, home addresses, employee IDs, job titles, department structures, office locations, reporting hierarchies, group memberships, and service account details. Some entries apparently flag accounts with Global Administrator privileges, which is exactly the kind of information you'd want if you were planning a follow-up phishing campaign. No passwords needed when you already know who holds the keys.

How TheHatman actually got in is the question nobody can answer yet. The attacker claims compromised credentials were used, but Hudson Rock couldn't verify the initial access method. The firm suggested a few plausible routes: infostealer malware harvesting credentials or session cookies, phishing, weak or missing multifactor authentication, or overly permissive third-party app integrations.

Interestingly, Hudson Rock said its own infostealer database contains compromised Microsoft cloud credentials linked to most of the named companies, though it couldn't directly connect those credentials to TheHatman's alleged access.

The firm's working theory is that this looks more like targeted exploitation of existing infostealer infections than some novel Azure vulnerability. The logic being: if there were a systemic flaw in Azure or Entra, you'd expect a far messier, broader set of victims rather than a tidy collection of Fortune 500 names.

Tata Consultancy Services is the only company to have publicly responded so far, filing a statement with India's stock exchange. TCS said it found 'no credible evidence of a breach' of its systems or customer environments. It also noted that the data referenced appears to be over four years old and limited to basic employee information. On the attack method, TCS said TheHatman claimed to have used password spraying and MFA fatigue techniques, but that the company has had controls against both in place for more than two years.

The Register reached out to all named organisations, and to Microsoft, asking whether any breach occurred and whether a broader campaign targeting Azure customers is under investigation. Most haven't responded publicly.

Someone claims to have millions of records from nine major corporate directories. How they got them remains an open question.

READ NEXT
Hacker Flogs Azure Directory Data From McDonald's, Vodafone and a Stack of Fortune 500 NamesSnowflake Breach Hacker Pleads Guilty: 100 Million Records, Stale Passwords, and No MFAFrench Tax Authority Breach Exposes Financial Data on 680,000 Citizens