A threat actor known as 'TheHatman' is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of several Fortune 500 companies, including TCS and McDonald's.
- Threat actor 'TheHatman' claims to possess 3.64 million Azure account records.
- McDonald's (1.7M) and TCS (800K) are among the largest alleged data dumps.
- Attack vectors reportedly include password spraying and MFA fatigue.
- TCS and Gap Inc. deny current breaches, claiming the data is outdated.
In a significant escalation of cloud-based cyber threats, a threat actor operating under the alias 'TheHatman' has claimed to have exfiltrated massive employee databases from the Microsoft Azure infrastructure of several Fortune 500 organizations. The stolen data is currently being advertised for sale on underground forums.
The most substantial breach involves McDonald's Corporation, with an alleged 1.7 million employee records stolen directly from their Azure Tenant. The leaked datasets reportedly contain highly specific details, including full names, employee IDs, professional email addresses, job titles, phone numbers, and physical postal addresses.
Why This Matters
BozokMedia analysis shows that the real danger lies not in the age of the data, but in the exposure of service accounts and global administrator names. Even if the records are several years old, this structural information allows attackers to conduct highly targeted spear-phishing campaigns. By knowing who the admins are, hackers can craft believable lures to gain high-level access to current corporate environments.
"Once attackers possess valid credentials, the efficacy of traditional perimeter defenses drops by nearly 63%."
Responding to the allegations, Tata Consultancy Services (TCS) notified the National Stock Exchange of India, stating that their internal investigation found no credible evidence of a recent breach. TCS asserted that the data appears to be at least four years old and that the company has employed robust safeguards against password spraying and MFA fatigue for over two years.
Similarly, Gap Inc. stated that their preliminary investigation suggests the data is limited in scope and non-sensitive. The company emphasized that there is no evidence to suggest their current corporate systems have been compromised.
Cyber intelligence firm Hudson Rock analyzed the samples provided by the hacker and confirmed the presence of "foundational corporate directory attributes," including .onmicrosoft.com structures. While the authenticity of the data is highly probable, the exact method of exfiltration remains a mystery.
| Company | Record Size | Data Type |
|---|---|---|
| McDonalds | 1.7+ Million | Internal Employee Dump |
| TCS | 800,000+ | Azure Dump |
| Vodafone | 425,000+ | Internal Employee Dump |
| HCL Tech | 250,000+ | Azure Dump |
Frequently Asked Questions
1. What is an Azure Tenant? An Azure Tenant is a dedicated instance of Microsoft Entra ID (formerly Azure AD) that represents a single organization.
2. How can employees protect themselves? Use unique, complex passwords for every account and be wary of unexpected MFA prompts on your mobile device.