Fortune 500 Companies Hit in Azure Data Theft Campaign
Threat actor 'TheHatman' is selling millions of records allegedly exfiltrated from Azure/Entra tenants of major Fortune 500 companies including McDonald's, TCS, Vodafone, and IHG Data was stolen using leaked credentials from a targeted infostealer campaign, containing internal employee directories with names, emails, phone numbers, job titles, and privileged account details McDonald's dump is the largest at 1.7 million records, followed by TCS (800K), Vodafone (425K), HCL Technologies (250K), an
Analysis
TL;DR
- Threat actor 'TheHatman' is selling millions of records allegedly exfiltrated from Azure/Entra tenants of major Fortune 500 companies including McDonald's, TCS, Vodafone, and IHG
- Data was stolen using leaked credentials from a targeted infostealer campaign, containing internal employee directories with names, emails, phone numbers, job titles, and privileged account details
- McDonald's dump is the largest at 1.7 million records, followed by TCS (800K), Vodafone (425K), HCL Technologies (250K), and IHG (185K)
- The exposure of service accounts and global admin names provides attackers a direct roadmap for social engineering, spear-phishing, and privilege escalation attacks
- Hudson Rock identified stolen credentials linked to most affected organizations, confirming a targeted rather than opportunistic attack campaign
Why It Matters
This incident highlights the critical intersection of credential hygiene and cloud security at enterprise scale, demonstrating how compromised Azure/Entra credentials can lead to massive internal directory exposure across multiple industries. For AI practitioners and security professionals, it underscores the importance of monitoring for infostealer infections and implementing strict conditional access policies to prevent lateral movement within cloud tenants.
Technical Details
- The attack vector was a targeted infostealer campaign that compromised Azure/Entra credentials, allowing the threat actor to access and export internal employee directories that match Azure directory export formats
- Exfiltrated fields include foundational corporate directory attributes: employee names, corporate email addresses, physical addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, and highly privileged account records
- The victimology spans multiple sectors including IT services (TCS, HCL, Kyndryl, Hexaware), hospitality (IHG, Wyndham), telecommunications (Vodafone), and retail (McDonald's, Gap Inc.), suggesting a broad but targeted campaign
- Hudson Rock's analysis confirmed stolen credentials were linked to most affected organizations, and the consistent field patterns across dumps indicate automated exfiltration tools were used to export Azure AD directory data
Industry Insight
- Organizations should immediately audit their Azure/Entra environments for signs of infostealer compromise, implement mandatory hardware-based MFA, and review conditional access policies to detect anomalous directory export activities
- The exposure of service accounts and privileged admin names creates a direct attack surface for BEC and spear-phishing campaigns; security teams should treat this data as actively weaponizable and accelerate incident response timelines
- Cloud directory hygiene must become a board-level concern—regular credential rotation, just-in-time privileged access, and continuous monitoring for directory export anomalies are now essential controls for any organization using Azure/Entra at scale
Disclaimer: The above content is generated by AI and is for reference only.