Massive Azure Credential Theft Campaign Targets Fortune 500 Companies

A threat actor operating under the alias “TheHatman” has claimed to have stolen approximately 3.64 million employee and tenant records from the Azure and Entra environments of multiple major organizations. The alleged victims include McDonald’s, Tata Consultancy Services, Vodafone, HCL Technologies, Kyndryl, Gap Inc., InterContinental Hotels Group, and Wyndham Hotels. The actor claims to have obtained the information using compromised credentials and is advertising the datasets for sale on cybercrime forums. The alleged records include employee names, corporate email addresses, employee IDs, job titles, phone numbers, physical addresses, service accounts, and other tenant information.

The largest alleged dataset involves McDonald’s, with the threat actor claiming approximately 1.7 million records, followed by more than 800,000 records allegedly belonging to Tata Consultancy Services and approximately 425,000 associated with Vodafone. Security researchers have examined samples from some of the datasets and found evidence suggesting that at least portions of the information may be genuine. However, the overall scale and age of the data remain uncertain. TCS has stated that its investigation found no credible evidence of a breach of its systems or customer environments and said the information attributed to the company appears to be at least four years old. Researchers have also identified compromised Azure credentials associated with infostealer infections at several of the named organizations, although this does not establish that infostealers were responsible for every alleged compromise.

The campaign highlights the growing risk posed by stolen cloud credentials and infostealer malware to enterprise identity environments. Even where the leaked information does not provide direct access to corporate systems, employee directories can expose organizational structures, service accounts, administrator identities, and reporting relationships that can support targeted phishing, credential attacks, and further compromise. Organizations should review Entra and Azure authentication logs for anomalous access, investigate credentials exposed through infostealer infections, enforce phishing-resistant MFA for privileged accounts, and rotate potentially compromised credentials and tokens. The incident also demonstrates why cloud identity security must be treated as an extension of endpoint security, since credentials stolen from a single infected workstation can potentially expose information across an organization’s cloud environment.

Share

Related Posts

bw-blog_un-1764705703306-e20b4b482ce1
kevin-shi-f2krpIYBrJc-unsplash
tsd-studio-r5hWJI-LmgA-unsplash

Copyright © All Right Reserved

Privacy Policy