Azure Credential Theft Exposes Millions of Records from McDonald's, Vodafone
A threat actor is selling internal employee directories stolen from the Azure and Entra tenants of several Fortune 500 companies.
A credential theft campaign has exposed the internal employee directories of several global corporations, including McDonald's and Vodafone. The data, stolen from Azure and Entra tenants, is currently being sold by a threat actor known as 'TheHatman.'
The breach resulted in the exposure of millions of enterprise records. McDonald's Corporation was the hardest hit with over 1.7 million records leaked, followed by Tata Consultancy Services (TCS) with approximately 800,000 records and Vodafone with roughly 425,000. Other affected organizations include HCL Technologies (250,000), IHG (185,000), Kyndryl (170,000), Gap Inc. (80,000), Hexaware (20,000), and Wyndham Hotels (9,000).
The Mechanics of the Breach
Researchers from Hudson Rock identified that compromised Azure credentials for several targeted firms—specifically TCS, Gap Inc., HCL Technologies, and Kyndryl—were tied to infostealer infections. These malware strains harvest credentials and session tokens directly from compromised user devices, allowing attackers to bypass traditional security perimeters.
Hudson Rock noted that given the scale of the impacted organizations, the campaign likely stems from the targeted exploitation of these infostealer infections rather than a systemic zero-day vulnerability within the Azure platform itself. The stolen datasets follow standard Azure directory export templates, containing corporate email domains and tenant-specific onmicrosoft.com addresses.
Strategic Risks to the Enterprise
The exposure of structured organizational hierarchies provides a high-fidelity blueprint for future attacks. By accessing detailed manager-to-employee relationships and privileged account mappings, threat actors can launch highly convincing spear-phishing and Business Email Compromise (BEC) campaigns. Attackers can impersonate specific executives or IT staff with precision, increasing the likelihood that employees will surrender multi-factor authentication (MFA) codes or approve fraudulent financial transfers.
Furthermore, the incident underscores the critical vulnerability of session token theft. Because infostealers can capture active session cookies, attackers can often maintain access to corporate environments without needing to re-authenticate, effectively neutralizing the protections offered by standard MFA implementations.
Future Outlook
Security teams are now tasked with auditing their Azure and Entra environments for unauthorized access and monitoring for unusual activity originating from compromised accounts. While the current leak focuses on directory information, the presence of service account details and Global Administrator listings in the datasets suggests a high risk of further escalation.
Organizations are encouraged to prioritize the remediation of infostealer infections on endpoints and to implement more robust session management policies to mitigate the risk of token theft. It remains to be seen if 'TheHatman' will release further datasets or if other Fortune 500 companies have been similarly compromised but not yet identified.