Critical Azure Vulnerability Exposes Millions of Enterprise Records
Key Takeaways A threat actor known as “TheHatman” is actively selling stolen internal employee directories from major global corporations on dark web forums. The data, reportedly...
Key Takeaways
- A threat actor known as “TheHatman” is actively selling stolen internal employee directories from major global corporations on dark web forums.
- The data, reportedly exfiltrated from Azure and Entra tenants using compromised credentials, includes sensitive information like corporate email addresses, job titles, and even details on Global Administrator accounts.
- At least nine Fortune 500-level companies across various sectors, including McDonald’s, Tata Consultancy Services, and Vodafone, have had their employee data exposed, with millions of records now for sale.
- While the exact method of initial intrusion is unconfirmed, researchers suggest infostealer malware is a likely vector, having identified compromised Azure credentials tied to such infections at several affected firms.
- Organizations are urged to enhance credential hygiene, enforce multi-factor authentication, and monitor for infostealer activity to mitigate risks.
Extensive Azure Data Exfiltration Campaign Uncovered
A significant data exfiltration operation is unfolding on dark web marketplaces, where a threat actor identified as “TheHatman” is actively marketing internal employee directories purportedly stolen from numerous large enterprises. These sensitive records are claimed to have been extracted directly from the victim organizations’ Azure and Entra tenants, leveraging compromised credentials.
Table Of Content
Over the past week, TheHatman has populated underground forums with listings for data originating from at least nine companies, many of which are Fortune 500-level entities. The affected sectors span IT services, hospitality, telecommunications, retail, and logistics, indicating a broad targeting scope rather than a specific industry focus.
Prominent Victims and Exposed Data Volume
The scale of the exposed data is substantial. McDonald’s Corporation leads the list with over 1.7 million records reportedly compromised. Other major victims include Tata Consultancy Services (TCS) with approximately 800,000 records, Vodafone with around 425,000, and HCL Technologies with an estimated 250,000 records.
Further organizations impacted in this campaign are InterContinental Hotels Group, with about 185,000 records, Kyndryl with 170,000, Gap Inc. with 80,000, Hexaware Technologies with 20,000, and Wyndham Hotels with 9,000 records.
Azure Credential Theft Campaign Details
Researchers at Hudson Rock, who have examined sample datasets, have corroborated the credibility of the information. They noted that the corporate email domains and field structures within the samples align precisely with typical Azure directory exports, lending weight to TheHatman’s claims.
The leaked datasets consistently adhere to a specific template. Core fields include full names, corporate email addresses (both from active company domains and tenant-specific onmicrosoft.com structures), phone numbers, and physical addresses. Beyond these basic contact details, the compromised data also exposes organizational specifics such as employee IDs, job titles, departmental affiliations, manager assignments, and direct reporting structures.
A particularly concerning aspect of these data dumps is the inclusion of access and group mapping information. This encompasses details about service accounts and, in some instances, listings of Global Administrator accounts. The exposure of such privileged account data provides adversaries with a ready-made blueprint for orchestrating highly effective spear-phishing attacks, social engineering schemes, and targeted privilege escalation within the victim organizations.
Unconfirmed Initial Access Vector
The precise method of initial intrusion remains unconfirmed. TheHatman has consistently stated that the data was acquired “using compromised credentials.” However, Hudson Rock researchers note that the exact entry point into these corporate networks has yet to be definitively identified.
Potential explanations for the breaches include infostealer malware, which can harvest session tokens directly from employee workstations; sophisticated phishing campaigns designed to yield administrative-level access; Azure tenants lacking robust multi-factor authentication (MFA) enforcement; or the exploitation of third-party APIs or integrations with overly broad read permissions. The rapid and consistent nature of the data dumps suggests a systematic, potentially automated, process once an initial foothold was established within the target environments.
Supporting the infostealer theory, Hudson Rock researchers have reported identifying compromised Azure credentials linked to infostealer infections at several of the affected companies. These include machines traced to employees at TCS, Gap Inc., HCL Technologies, and Kyndryl. One particular compromised device reportedly contained dozens of corporate credentials and hundreds of sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account. The fact that this campaign targets primarily massive multinational corporations, rather than a broad spectrum of smaller businesses, suggests a focused exploitation of stolen credentials rather than an underlying vulnerability within the Azure platform itself.
The ramifications of this data leak extend far beyond the initial exposure. Threat actors frequently weaponize structured directory data to execute convincing business email compromise (BEC) and spear-phishing operations. By leveraging accurate reporting lines and job titles, they can impersonate managers or IT staff, tricking employees into approving fraudulent financial transfers or divulging MFA codes. The exposure of service accounts and administrator names also serves as a critical targeting map for initial access brokers and ransomware groups seeking the most efficient pathways into an organization’s critical infrastructure.
What You Should Do
- Enforce Multi-Factor Authentication (MFA): Implement mandatory MFA for all Azure and Entra tenant accounts, especially for administrative roles.
- Monitor for Infostealer Activity: Deploy robust endpoint detection and response (EDR) solutions and actively monitor for signs of infostealer malware on employee workstations. Regularly scan for compromised credentials on dark web monitoring services.
- Strengthen Credential Hygiene: Educate employees on phishing awareness and the risks associated with reusing passwords or using weak credentials. Implement strong password policies.
- Review Third-Party Permissions: Regularly audit and restrict permissions for all third-party applications and APIs integrated with Azure, ensuring they operate with the principle of least privilege.
- Conduct Regular Security Audits: Perform frequent security assessments of your Azure and Entra configurations to identify and remediate potential vulnerabilities or misconfigurations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.