Massive Azure exfiltration campaign exposes 3.6 million employee records of major companies

A threat actor known as “TheHatman” is offering millions of employee records allegedly stolen from the Azure/Entra ID environments of major companies, including McDonald’s, TCS, Vodafone, HCL Technologies, IHG, Kyndryl, Gap, Hexaware, and Wyndham. The listings claim approximately 3.64 million records in total, with the largest being a purported 1.7 million-record McDonald’s database. The exposed information reportedly includes names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, managers, direct reports, group memberships, service accounts, and Global Administrator information.

Cybersecurity researchers found strong evidence that at least the McDonald’s 8,000-record sample is a genuine Azure/Entra directory export, including authentic corporate domains, Microsoft tenant addresses, export-specific field names, and characteristic encoding errors. However, the sample cannot establish when the data was obtained or whether the seller’s claimed 1.7 million-record total is accurate. The same seller reportedly posted nine similar databases using nearly identical schemas and wording, suggesting a systematic process for obtaining directory data from multiple organizations.

Researchers believe compromised credentials, potentially obtained through infostealer malware, are a likely explanation, although the precise intrusion method has not been confirmed. Tata Consultancy Services said its investigation found no credible evidence of a breach and indicated that its advertised data appeared to be at least four years old, while Gap likewise reported no evidence that its corporate systems had been compromised and said its data was several years old and non-sensitive.

Although passwords and password hashes were reportedly absent from the McDonald’s sample, the detailed organizational information could enable highly convincing phishing, business-email-compromise, impersonation, and social-engineering attacks. Overall, researchers consider the data highly likely to be authentic in at least some cases, but the extent, age, source, and compromise status of the advertised databases remain uncertain, and researchers could not independently verify their authenticity.

Read more about it here.

Chess.com data leak exposes 7.3 million players

The reported leak involves 7,337,396 Chess.com account records, distributed as a 744 MB 7-Zip file that expands to a 15.5 GB tab-separated table. The database reportedly contains 4,656,791 email addresses, along with usernames, account IDs/UUIDs, first and last names, countries, locations, locales, chess titles, ratings, skill levels, premium/subscription status, verification and activation flags, member-since dates, and last-login timestamps. Some records also contain avatar links and internal Google Ad Manager audience-segmentation tags, including coaching experiments, trial eligibility, lapsed-user groups, and rating-based targeting. No passwords, password hashes, or payment information were found, meaning the leaked data alone does not appear sufficient to directly log into affected accounts.

Evidence suggests the data is genuine and was likely obtained through large-scale scraping rather than a conventional server breach. Researchers found that version-1 account UUIDs contained embedded timestamps matching account-registration dates across a sample of 200,000 records. The records were collected in daily batches over nine consecutive days, and approximately 7.4% appeared more than once, consistent with repeated automated collection. The technique also appears similar to Chess.com’s 2023 incidents, when approximately 828,000 records and then another 476,000 records were scraped, reportedly by abusing the platform’s find-friends functionality. However, the presence of internal advertising-audience data raises questions about whether the latest collection involved an authenticated or internal-facing endpoint rather than only publicly accessible information.

Although the absence of passwords and payment data significantly limits the immediate account-takeover risk, the leaked information still provides valuable material for phishing and social engineering. A scammer could use a real email address, name, country, chess rating, and subscription status to create a convincing fake Chess.com message about a tournament invitation, membership renewal, account-security alert, or fair-play issue. Chess.com users should therefore treat unexpected emails or messages referencing their accounts with extra suspicion and avoid clicking login links; instead, they should go directly to Chess.com through their browser or app.

Read more about it here.

CareCloud data breach exposes medical and financial data of 345,000 people

US health tech giant CareCloud started notifying 350,000 people that their information was stolen in a data breach. Hackers accessed one of its AWS environments between March 10 and March 16, and likely exfiltrated data from it.

The initial March 27 disclosure to regulators didn’t provide much details. On June 24, the investigation determined that personal, financial, and medical information was compromised in the incident.

Stolen data included people’s names, postal addresses, Social Security numbers, as well as government-issued identification numbers, such as passports and driver’s licenses. The stolen data included financial information, such as bank account information and payment card numbers, including in some cases the CVV of credit cards, alongside a wealth of medical and health-related information.

Read more about it here.