CyberSecurity

Fortune 500 Firms Hit in Azure Data Theft Campaign: Millions of Employee Records for Sale

Published

on

Millions of Records from Corporate Giants Up for Sale

A cybercriminal operating under the alias ‘TheHatman’ is hawking what appears to be a treasure trove of corporate data — millions of employee records allegedly pulled directly from the Microsoft Azure tenants of some of the world’s most recognizable brands.

The list of supposedly affected companies reads like a who’s who of the Fortune 500: McDonald’s, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. If the claims hold up, this is a massive Azure data theft incident with far-reaching implications.

Security research firm Hudson Rock, which first flagged the campaign, says the stolen data appears to be the real deal. The datasets contain internal employee directories that line up with Azure directory exports based on email addresses and field names.

What’s in the Stolen Data?

The sheer volume is staggering. The McDonald’s dump alone reportedly contains over 1.7 million records. TCS follows with 800,000, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000.

Across all the affected tenant dumps, the leaked fields are consistent — and they’re not just names and email addresses. The exfiltrated information includes:

  • Employee names and corporate email addresses
  • Physical addresses and phone numbers
  • Employee IDs and job titles
  • Manager details and user group membership
  • Service accounts and highly privileged account records

That last bullet point is what keeps security professionals up at night. Hudson Rock notes that the exposure of service accounts and global admin names is particularly concerning, as it provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations.

How Did This Happen?

According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials. Hudson Rock’s analysis supports this theory — the firm identified stolen credentials linked to most of the affected organizations, likely compromised in a targeted infostealer campaign.

The victimology suggests this wasn’t a random smash-and-grab. The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics. That’s a deliberate pattern, not a scattergun approach.

The Infostealer Connection

Infostealer malware has become the bane of enterprise security. These malicious programs quietly siphon credentials from infected devices, often going unnoticed for months. When those credentials belong to employees with access to cloud infrastructure, the results can be catastrophic — as this campaign demonstrates.

Immediate Threats to Victim Organizations

Hudson Rock warns that the stolen data poses an immediate threat to the affected companies. Attackers can now map internal reporting structures and identify high-value targets. That’s the kind of intelligence that makes spear-phishing and business email compromise (BEC) attacks far more convincing.

Think about it: an email that appears to come from your actual manager, referencing your actual project, with your actual phone number in the signature block. That’s not a generic phishing attempt — that’s a precision strike.

For more on how similar incidents unfold, check out our coverage of the RingCentral data breach and the massive password spray campaign targeting Azure CLI.

What Organizations Should Do Now

While the full scope of this Azure data theft campaign is still unfolding, there are immediate steps companies should consider:

  1. Audit Azure AD and Entra ID logs for suspicious activity, especially around service accounts and privileged roles.
  2. Rotate credentials for any accounts that may have been exposed, particularly global admins.
  3. Enforce multi-factor authentication (MFA) across all user accounts, especially privileged ones.
  4. Monitor for infostealer infections on employee devices, as these often precede cloud account compromises.
  5. Review user group memberships and remove unnecessary access rights.

The fact that this data is already being sold on underground forums means the window for preventive action is closing fast. For the affected organizations, the focus now shifts to damage control and threat intelligence.

Hudson Rock’s findings also serve as a stark reminder that cloud security is only as strong as the credentials protecting it. A single compromised laptop can unravel an entire enterprise’s defenses.

As the investigation continues, expect more details to emerge about how TheHatman pulled off this audacious heist — and what it means for the future of cloud security.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version