Threat Actor 'TheHatman' Sells Stolen Azure Directories from Fortune 500 Firms
Millions of employee records from McDonald's, Vodafone, and others were exfiltrated via compromised credentials.
A threat actor operating under the moniker 'TheHatman' is selling massive internal employee directories stolen from several Fortune 500 companies. The data was exfiltrated from Microsoft Azure and Entra ID tenants using compromised credentials, exposing millions of records across the hospitality, telecommunications, and IT services sectors.
McDonald’s Corporation emerged as the most heavily impacted organization, with over 1.7 million exposed records. Other major victims include Tata Consultancy Services with approximately 800,000 records, Vodafone with 425,000, HCL Technologies with 250,000, and Kyndryl with 170,000. The stolen datasets are highly detailed, containing full names, corporate emails, phone numbers, physical addresses, and employee IDs. Additionally, the breach exposed job titles, department affiliations, manager assignments, and critical service account details.
The Attack Vector
This campaign appears to be a systematic operation targeting large multinational firms rather than a flaw in the Azure platform itself. Researchers from Hudson Rock identified compromised Azure credentials tied to infostealer infections for employees at Kyndryl, HCL Technologies, Gap Inc., and TCS. The threat actor likely used this infostealer malware to harvest session tokens and credentials directly from employee machines, which then allowed them to query Entra ID directories and export structured organizational data.
Industry Implications
The exposure of detailed organizational hierarchies and privileged account names, including Global Administrators, provides a strategic blueprint for future attacks. By possessing precise data on who reports to whom and which accounts hold administrative power, attackers can launch highly targeted spear-phishing and Business Email Compromise (BEC) campaigns. This level of detail allows criminals to impersonate managers or IT staff with high precision, increasing the likelihood that employees will surrender multi-factor authentication (MFA) codes or approve fraudulent financial transfers.
What to Watch
While the primary targets have been identified, the full scope of the breach remains fluid as 'TheHatman' continues to market the data. Security teams are now tasked with auditing Entra ID logs for unauthorized directory queries and forcing password resets for accounts flagged by infostealer telemetry. It remains to be seen if the threat actor will leverage the service account details to move laterally within the affected networks or if the operation will remain focused on the sale of the directories themselves.