< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Azure credential theft campaign exposes millions of records from Fortune 500 companies

A massive data exfiltration campaign targeting Microsoft Azure and Entra ID tenants has exposed millions of internal employee records from several Fortune 500 companies. A threat actor operating under the alias ‘TheHatman’ is reportedly selling these stolen directories on the dark web.

McDonald’s Corporation is among the most heavily impacted, with approximately 1.7 million records exposed. Other major organizations affected include Tata Consultancy Services (~800,000 records), Vodafone (~425,000), HCL Technologies (~250,000), Kyndryl (~170,000), and InterContinental Hotels Group (~185,000). The breach spans multiple sectors, including telecommunications, hospitality, retail, and IT services.

The stolen data includes full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, and organizational hierarchies. Critically, the datasets contain access and group mapping information, such as service account details and Global Administrator records. Researchers suggest the attacker likely used compromised credentials or session token theft to bypass security and access the directories via the Azure CLI and portals. This intelligence significantly increases the risk of advanced spear-phishing, business email compromise, and ransomware attacks.

Entities

McDonald's Corporation · Microsoft Azure · Tata Consultancy Services · TheHatman · Vodafone