A threat actor known as “TheHatman” is selling millions of employee records stolen directly from Azure tenants of major Fortune 500 firms. The breach includes data from McDonald’s, TCS, Vodafone and others, giving cybercriminals a precise map for future attacks.
Key Takeaways
- Over 1.7 million McDonald’s records exfiltrated from Azure
- Data includes emails, phone numbers, job titles and privileged accounts
- Leaked credentials enable targeted spear‑phishing and privilege‑escalation campaigns
A threat actor using the moniker “TheHatman” has begun selling data allegedly stolen directly from Azure tenants of several Fortune 500 organizations. The stolen datasets contain internal employee directories from well‑known brands such as McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), and others.
According to Hudson Rock, the exfiltration was performed via compromised Azure/Entra credentials, yielding exports that mimic legitimate Azure directory dumps. The largest dump belongs to McDonald’s with more than 1.7 million records, followed by TCS (800 k), Vodafone (425 k), HCL (250 k) and IHG (185 k).
Why This Matters
BozokMedia analysis shows that exposure of service accounts and global admin names provides attackers a ready‑made roadmap for spear‑phishing, business‑email‑compromise and privilege‑escalation attacks against these global enterprises.
"Such a massive breach of Azure directories can cripple an organization’s security posture overnight," says cybersecurity analyst Dr. Riya Sharma.
The compromised data includes employee names, corporate email addresses, physical addresses, phone numbers, employee IDs, job titles, manager details, group memberships, service accounts, and highly privileged account records. This information allows threat actors to map internal reporting structures and launch convincing social‑engineering campaigns.
Frequently Asked Questions
Does this breach affect all Azure tenants? No, it only impacts tenants where the leaked credentials were used to gain access.
How can organizations mitigate this risk? Implement multi‑factor authentication, conduct regular credential audits, and monitor for anomalous access patterns.