Azure Credential Theft Exposes Millions of Enterprise Records

A significant data breach has surfaced, involving the unauthorized sale of internal employee directories from several major corporations. The threat actor, known as “TheHatman,” claims to have extracted these records directly from the Azure and Entra tenants of the affected organizations using compromised credentials.

Over the past week, TheHatman has listed data from at least nine Fortune 500 companies across various sectors, including IT services, hospitality, telecommunications, retail, and logistics. Notable victims include McDonald’s Corporation, with over 1.7 million records exposed; Tata Consultancy Services, approximately 800,000 records; Vodafone, around 425,000 records; and HCL Technologies, about 250,000 records. Other affected entities are InterContinental Hotels Group (185,000 records), Kyndryl (170,000), Gap Inc. (80,000), Hexaware Technologies (20,000), and Wyndham Hotels (9,000).

Analysts from Hudson Rock have reviewed sample datasets and found them to be highly credible. The data includes corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager assignments, and direct reports. Alarmingly, some datasets also reveal access and group mapping information, such as service account details and listings of Global Administrator accounts. This level of detail provides a roadmap for potential spear-phishing, social engineering, and privilege escalation attacks.

The exact method of intrusion remains unconfirmed. TheHatman has indicated that the data was obtained using compromised credentials, but the specific entry points are still under investigation. Potential vectors include infostealer malware harvesting session tokens from employee devices, phishing campaigns yielding administrative access, tenants lacking strict multi-factor authentication (MFA) enforcement, or exploitation of third-party APIs with excessive read permissions. The rapid and consistent nature of the data dumps suggests a systematic, possibly automated, process following initial access.

Supporting the infostealer theory, Hudson Rock researchers have identified compromised Azure credentials linked to infostealer infections in several of the affected companies, including TCS, Gap Inc., HCL Technologies, and Kyndryl. One compromised device reportedly contained numerous corporate credentials and sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account. The focus on large multinational firms suggests targeted exploitation of stolen credentials rather than a broader vulnerability within the Azure platform.

The implications of this breach extend beyond the initial data exposure. Threat actors can leverage the detailed directory information to conduct convincing business email compromise and spear-phishing campaigns, impersonating managers or IT staff to deceive employees into approving fraudulent transactions or disclosing MFA codes. The exposure of service accounts and administrator names also provides a targeting map for initial access brokers and ransomware groups seeking entry into critical infrastructure.

This incident underscores the critical importance of robust credential management and security practices. Organizations must prioritize continuous monitoring for compromised credentials, enforce MFA across all tenant portals, and scrutinize third-party API permissions to mitigate the risk of such breaches.