Hacker claims 3.6 million Azure accounts stolen from major companies

The threat actor claims that Azure is a massive theft of data from large companies

A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.

​Since July 31, multiple posts by someone using the pseudonym “TheHatman” have advertised data dumps from major organizations, including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG) and Kyndryl.

In total, the threat claimed to have 3.64 million data records, with the latest breach published on Sunday containing an alleged 1.7 million records of McDonalds employees.

image

“I am selling an internal dump of McDonald’s Corporation employees downloaded directly from Azure Tenant using compromised credentials,” the threat actor says in the post.

TheHatman says the information includes names, employee IDs, email addresses, job titles, phone numbers, mailing addresses, service accounts and other tenant account records.

McDonald's cybercriminal advertising database of employee records
McDonald’s cybercriminal advertising database of employee records
source: BleepingComputer

The second largest advertised data dump was allegedly stolen from Tata Consultancy: an Azure dump with more than 800,000 employee records “downloaded directly from the Azure Tenant using compromised credentials,” the cybercriminal stated.

However, in a notification to the National Stock Exchange of India, Tata said it investigated the alleged breach and found “no credible evidence of a breach of TCS systems or the customer environment”.

The company says the details appear to be at least four years old and include only basic employee information.

“The attacker claimed to have used password spray and multi-factor authentication (MFA) fatigue as an attack vector. The company has had strong safeguards against such techniques for over two years,” Dad says.

The company also added that it had reviewed its defenses and found that they remained effective.

In a statement to BleepingComputer, a spokesperson for Gap Inc. said the company had found no evidence of wrongdoing. Furthermore, the advertised data is not sensitive in nature and “dates back several years”.

“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated several years ago. Of note, there is no evidence to suggest that our corporate systems were compromised,” said the Gap Inc. representative.

Between July 31 and August 16, TheHatman offered to sell data dumps to the following organizations:











Company Size Type Data type
McDonald’s 1.7+ million records Azure employee attrition internally Full name, email, title, phone, address
Gap Inc. 80,000+ records Azure employee attrition internally Full name, email, title, phone, address
Vodafone 425,000+ records Azure employee attrition internally Full name, email, title, phone, address
TCS (Tata Consultancy) 800,000+ records Azure dump Full name, email, title, phone, address
HCL Technologies 250,000+ records Azure dump Full name, email, title, phone, address
InterContinental Hotels 185,000+ records Azure dump Full name, email, title, phone, address
Wyndham Hotels 9000+ records Azure/Entra dump Full name, email, title, phone, address
Hexaware 20,000+ records Azure/Entra dump Full Name, Email, Employee ID, Phone, Address
Kyndryl.com 170,000+ records Azure/Entra dump Employee accounts, service accounts and other tenant account records.

For each advertised database, TheHatman also provided a sample database for potential buyers to check out.

Cyber ​​crime intelligence company Hudson Rock analyzed the leaks and confirmed that they contain “root enterprise directory attributes” and a clear data structure with fields that include “active domains and client-specific .onmicrosoft.com structures.”

According to the cybersecurity firm, the dumps also contain service accounts and global administrator names, which could facilitate social engineering and phishing attacks.

While Hudson Rock has high confidence that the data is authentic, the access vector and exfiltration method remain unknown. BleepingComputer has not been able to independently verify that the data is authentic.

BleepingComputer contacted the companies listed about the potential breach, but did not receive comment by the time of publication.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *