Threat Actor Sells 3.6 Million Azure Employee Records from Fortune 500 Firms
Hacker 'TheHatman' claims to have breached Azure and Entra tenants, though some victims argue the leaked data is years old.
A threat actor operating under the name 'TheHatman' claims to have stolen and is now selling approximately 3.6 million employee records from the Microsoft Azure and Entra tenants of several Fortune 500 companies. The breach highlights the persistent risk of credential theft within large-scale cloud environments.
According to reports from BleepingComputer and Help Net Security, the stolen data consists of internal directories. The alleged victims include some of the world's largest enterprises, with McDonald's estimated to have lost 1.7 million records, Tata Consultancy Services (TCS) 800,000, Vodafone 425,000, and HCL Technologies 250,000. Other organizations listed as targets include IHG, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.
The Intrusion Vector
Security researchers at Hudson Rock analyzed samples of the leaked data and believe the information is likely authentic. Their analysis suggests that the breach was not the result of a systemic zero-day vulnerability within the Azure platform itself. Instead, the researchers believe the attacker likely gained access through compromised credentials, potentially via Infostealer malware infections that captured session tokens or through targeted phishing campaigns aimed at administrative accounts.
However, not all alleged victims agree with the assessment of a current breach. Tata Consultancy Services (TCS) has denied that its systems were recently compromised, stating the company found no credible evidence of a breach of its own systems or customer environments. TCS further claimed that the data being sold appears to be more than four years old.
Why It Matters
The exposure of internal employee directories is a critical security failure because it provides a blueprint of an organization's internal structure. By obtaining job titles, manager hierarchies, and the specific names of Global Administrator accounts, attackers can move from a broad data leak to highly targeted attacks.
Hudson Rock researchers noted that the exposure of service accounts and global admin names is particularly concerning, as it provides a "direct roadmap" for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations.
What's Next
Industry observers are now watching to see if other listed companies will confirm the breach or, like TCS, claim the data is legacy information. The incident serves as a reminder for enterprise Azure users to implement stricter conditional access policies and monitor for the use of stolen session tokens, which can bypass traditional multi-factor authentication.