Massive Azure exfiltration campaign exposes 3.6 million employee records of major companies

A threat actor known as “TheHatman” is offering millions of employee records allegedly stolen from the Azure/Entra ID environments of major companies, including McDonald’s, TCS, Vodafone, HCL Technologies, IHG, Kyndryl, Gap, Hexaware, and Wyndham. The listings claim approximately 3.64 million records in total, with the largest being a purported 1.7 million-record McDonald’s database. The exposed information reportedly includes names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, managers, direct reports, group memberships, service accounts, and Global Administrator information.

Cybersecurity researchers found strong evidence that at least the McDonald’s 8,000-record sample is a genuine Azure/Entra directory export, including authentic corporate domains, Microsoft tenant addresses, export-specific field names, and characteristic encoding errors. However, the sample cannot establish when the data was obtained or whether the seller’s claimed 1.7 million-record total is accurate. The same seller reportedly posted nine similar databases using nearly identical schemas and wording, suggesting a systematic process for obtaining directory data from multiple organizations.

Researchers believe compromised credentials, potentially obtained through infostealer malware, are a likely explanation, although the precise intrusion method has not been confirmed. Tata Consultancy Services said its investigation found no credible evidence of a breach and indicated that its advertised data appeared to be at least four years old, while Gap likewise reported no evidence that its corporate systems had been compromised and said its data was several years old and non-sensitive.

Although passwords and password hashes were reportedly absent from the McDonald’s sample, the detailed organizational information could enable highly convincing phishing, business-email-compromise, impersonation, and social-engineering attacks. Overall, researchers consider the data highly likely to be authentic in at least some cases, but the extent, age, source, and compromise status of the advertised databases remain uncertain, and researchers could not independently verify their authenticity.

Read more about it here.

Leave a Reply

Your email address will not be published. Required fields are marked *