Threat Actor Sells 3.6 Million Azure Records from Fortune 500 Firms
Hacker 'TheHatman' is selling corporate directory data from McDonald's, Vodafone, and others, exposing high-level administrator identities.
A threat actor using the alias 'TheHatman' claims to have stolen and is currently selling approximately 3.64 million records exfiltrated from the Microsoft Azure and Entra ID environments of several Fortune 500 companies. The breach exposes a vast array of corporate directory attributes, providing a potential blueprint for future targeted attacks against some of the world's largest organizations.
According to the threat actor, the stolen data consists of internal employee dumps, service accounts, and tenant information. The scale of the alleged theft is significant, with McDonald's topping the list at over 1.7 million records. Other targeted entities include Tata Consultancy Services (800,000+), Vodafone (425,000+), HCL Technologies (250,000+), InterContinental Hotels Group (185,000+), Kyndryl (170,000+), Gap Inc. (80,000+), Hexaware (20,000+), and Wyndham Hotels (9,000+).
The exfiltrated data is comprehensive, including full names, email addresses, job titles, phone numbers, physical addresses, and employee IDs. Critically, the dumps also contain service account details and tenant account information, including listings of Global Administrators. TheHatman claims to have accessed these Azure tenants using compromised credentials, stating, "I am selling McDonald’s Corporation internal employee dumps that I downloaded directly from my Azure tenant using compromised credentials."
Analysis and Corporate Response
Cybercrime intelligence firm Hudson Rock analyzed samples of the data and expressed high confidence that the records are genuine. The firm cited consistent data structures and the presence of active .onmicrosoft.com structures as evidence of authenticity. While the threat actor and some reports mentioned password spraying and MFA fatigue as the primary attack vectors, Hudson Rock noted that the exact intrusion method remains unknown, though they suspect the use of infostealer infections.
Responses from the affected companies have been mixed. A spokesperson for Gap Inc. stated that the data in question is "limited in scope, non-sensitive, and dates back several years." Similarly, Tata Consultancy Services (TCS) asserted that its investigation found no "credible evidence of a breach of the TCS system or customer environment."
Industry Implications
Despite claims from some companies that the data is aged or non-sensitive, security experts warn that the breach poses a severe risk. The exposure of service account names and Global Administrator identities provides a roadmap for attackers to launch sophisticated social engineering, phishing, and spear-phishing campaigns. By knowing exactly who holds high-level privileges, attackers can craft highly convincing lures to gain deeper access to corporate networks.
What's Next
Organizations are now tasked with auditing their Azure tenant permissions and rotating credentials for high-value service accounts. While the authenticity of the data has been largely confirmed by third-party analysts, the full extent of the compromise—and whether the compromised credentials provided access to actual corporate data beyond directory attributes—remains to be fully determined.