An extensive Azure data breach is making waves on the dark web, as a cybercriminal known as “TheHatman” is selling internal employee directories from some of the largest corporations globally. This campaign involves compromised credentials from Azure and Entra tenants, revealing a substantial volume of sensitive enterprise data.
Massive Data Leak from Fortune 500 Companies
Within the past week, TheHatman has listed data from at least nine Fortune 500 companies on underground forums. These firms span across sectors such as IT services, hospitality, telecommunications, retail, and logistics. Notably, McDonald’s leads with over 1.7 million records exposed. Tata Consultancy Services follows with around 800,000, Vodafone with approximately 425,000, and HCL Technologies with about 250,000 records.
Other affected enterprises include InterContinental Hotels Group with 185,000 records, Kyndryl with 170,000, Gap Inc. with 80,000, Hexaware Technologies with 20,000, and Wyndham Hotels with 9,000.
Details of the Azure Credential Theft
Research by Hudson Rock confirms the authenticity of the leaked data, noting the matching corporate email domains and field structures typical of Azure directory exports. The datasets contain full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager assignments, and direct reports.
Particularly concerning is the inclusion of access and group mapping data, such as service account details and Global Administrator account lists. This information provides attackers with a detailed layout for executing spear-phishing, social engineering, and privilege escalation attacks.
Unclear Intrusion Methods and Ongoing Risks
The exact method of intrusion remains uncertain. While TheHatman claims the use of compromised credentials, the entry point is still unidentified. Potential scenarios include infostealer malware, phishing campaigns, inadequate multi-factor authentication, or exploitation of third-party APIs with excessive permissions.
Hudson Rock highlights findings of compromised Azure credentials linked to infostealer infections from affected companies, including TCS, Gap Inc., and Kyndryl. This incident underscores the targeted exploitation of stolen credentials rather than vulnerabilities within Azure itself.
The broader impact extends beyond the initial leakage. Cybercriminals can exploit the structured directory data for business email compromise and spear-phishing, impersonating managers or IT staff to deceive employees into fraudulent actions. The exposure of service accounts and administrator names also aids initial access brokers and ransomware groups in navigating critical infrastructures.
Organizations are advised to prioritize credential hygiene, implementing continuous monitoring for compromised credentials, enforcing MFA across all tenant portals, and scrutinizing third-party API permissions to mitigate vulnerabilities.
