Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Azure Vulnerability Exposes Millions of Enterprise Records
August 16, 2026
AWS Certificate Manager Ends Email Validation for Public Certificates
August 16, 2026
Microsoft Merges Consumer and Enterprise Copilot Apps
August 16, 2026
Home/CyberSecurity News/Critical Azure Vulnerability Exposes Millions of Enterprise Records
CyberSecurity News

Critical Azure Vulnerability Exposes Millions of Enterprise Records

Key Takeaways A threat actor known as “TheHatman” is actively selling stolen internal employee directories from major global corporations on dark web forums. The data, reportedly...

Jennifer sherman
Jennifer sherman
August 16, 2026 4 Min Read
3 0

Key Takeaways

  • A threat actor known as “TheHatman” is actively selling stolen internal employee directories from major global corporations on dark web forums.
  • The data, reportedly exfiltrated from Azure and Entra tenants using compromised credentials, includes sensitive information like corporate email addresses, job titles, and even details on Global Administrator accounts.
  • At least nine Fortune 500-level companies across various sectors, including McDonald’s, Tata Consultancy Services, and Vodafone, have had their employee data exposed, with millions of records now for sale.
  • While the exact method of initial intrusion is unconfirmed, researchers suggest infostealer malware is a likely vector, having identified compromised Azure credentials tied to such infections at several affected firms.
  • Organizations are urged to enhance credential hygiene, enforce multi-factor authentication, and monitor for infostealer activity to mitigate risks.

Extensive Azure Data Exfiltration Campaign Uncovered

A significant data exfiltration operation is unfolding on dark web marketplaces, where a threat actor identified as “TheHatman” is actively marketing internal employee directories purportedly stolen from numerous large enterprises. These sensitive records are claimed to have been extracted directly from the victim organizations’ Azure and Entra tenants, leveraging compromised credentials.

Table Of Content

  • Key Takeaways
  • Extensive Azure Data Exfiltration Campaign Uncovered
  • Prominent Victims and Exposed Data Volume
  • Azure Credential Theft Campaign Details
  • Unconfirmed Initial Access Vector
  • What You Should Do

Over the past week, TheHatman has populated underground forums with listings for data originating from at least nine companies, many of which are Fortune 500-level entities. The affected sectors span IT services, hospitality, telecommunications, retail, and logistics, indicating a broad targeting scope rather than a specific industry focus.

Prominent Victims and Exposed Data Volume

The scale of the exposed data is substantial. McDonald’s Corporation leads the list with over 1.7 million records reportedly compromised. Other major victims include Tata Consultancy Services (TCS) with approximately 800,000 records, Vodafone with around 425,000, and HCL Technologies with an estimated 250,000 records.

Further organizations impacted in this campaign are InterContinental Hotels Group, with about 185,000 records, Kyndryl with 170,000, Gap Inc. with 80,000, Hexaware Technologies with 20,000, and Wyndham Hotels with 9,000 records.

Azure Credential Theft Campaign Details

Researchers at Hudson Rock, who have examined sample datasets, have corroborated the credibility of the information. They noted that the corporate email domains and field structures within the samples align precisely with typical Azure directory exports, lending weight to TheHatman’s claims.

The leaked datasets consistently adhere to a specific template. Core fields include full names, corporate email addresses (both from active company domains and tenant-specific onmicrosoft.com structures), phone numbers, and physical addresses. Beyond these basic contact details, the compromised data also exposes organizational specifics such as employee IDs, job titles, departmental affiliations, manager assignments, and direct reporting structures.

A particularly concerning aspect of these data dumps is the inclusion of access and group mapping information. This encompasses details about service accounts and, in some instances, listings of Global Administrator accounts. The exposure of such privileged account data provides adversaries with a ready-made blueprint for orchestrating highly effective spear-phishing attacks, social engineering schemes, and targeted privilege escalation within the victim organizations.

Unconfirmed Initial Access Vector

The precise method of initial intrusion remains unconfirmed. TheHatman has consistently stated that the data was acquired “using compromised credentials.” However, Hudson Rock researchers note that the exact entry point into these corporate networks has yet to be definitively identified.

Potential explanations for the breaches include infostealer malware, which can harvest session tokens directly from employee workstations; sophisticated phishing campaigns designed to yield administrative-level access; Azure tenants lacking robust multi-factor authentication (MFA) enforcement; or the exploitation of third-party APIs or integrations with overly broad read permissions. The rapid and consistent nature of the data dumps suggests a systematic, potentially automated, process once an initial foothold was established within the target environments.

Supporting the infostealer theory, Hudson Rock researchers have reported identifying compromised Azure credentials linked to infostealer infections at several of the affected companies. These include machines traced to employees at TCS, Gap Inc., HCL Technologies, and Kyndryl. One particular compromised device reportedly contained dozens of corporate credentials and hundreds of sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account. The fact that this campaign targets primarily massive multinational corporations, rather than a broad spectrum of smaller businesses, suggests a focused exploitation of stolen credentials rather than an underlying vulnerability within the Azure platform itself.

The ramifications of this data leak extend far beyond the initial exposure. Threat actors frequently weaponize structured directory data to execute convincing business email compromise (BEC) and spear-phishing operations. By leveraging accurate reporting lines and job titles, they can impersonate managers or IT staff, tricking employees into approving fraudulent financial transfers or divulging MFA codes. The exposure of service accounts and administrator names also serves as a critical targeting map for initial access brokers and ransomware groups seeking the most efficient pathways into an organization’s critical infrastructure.

What You Should Do

  • Enforce Multi-Factor Authentication (MFA): Implement mandatory MFA for all Azure and Entra tenant accounts, especially for administrative roles.
  • Monitor for Infostealer Activity: Deploy robust endpoint detection and response (EDR) solutions and actively monitor for signs of infostealer malware on employee workstations. Regularly scan for compromised credentials on dark web monitoring services.
  • Strengthen Credential Hygiene: Educate employees on phishing awareness and the risks associated with reusing passwords or using weak credentials. Implement strong password policies.
  • Review Third-Party Permissions: Regularly audit and restrict permissions for all third-party applications and APIs integrated with Azure, ensuring they operate with the principle of least privilege.
  • Conduct Regular Security Audits: Perform frequent security assessments of your Azure and Entra configurations to identify and remediate potential vulnerabilities or misconfigurations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingransomwareThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

AWS Certificate Manager Ends Email Validation for Public Certificates

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Entra ID to Default to Passkeys, Retiring SMS and Voice MFA
August 15, 2026
AI Agents Persist, Rewrite Tools to Continue Attacks After Initial Malware Fails
August 14, 2026
Critical Citrix NetScaler Heap Overflow (CVE-2023-3519) Allows Remote Code Execution
August 14, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us