Fortune 500 companies fall victim to Azure data theft campaign

A threat actor is selling data allegedly stolen directly from Azure tenants to several Fortune 500 organizations.

Using the alias ‘TheHatman’, the threat actor offers millions of records apparently stolen from well-known brands such as McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels.

According to the threat, data was exfiltrated from Azure/Entra instances using leaked credentials.

The data contains internal employee directories that, based on the identified email addresses and field names that match the Azure directory export, appear to be legitimate, Hudson Rock says.

The McDonald’s dump is the largest, containing over 1.7 million records, followed by the TCS dataset with 800,000 records, Vodafone with 425,000, HCL Technologies with 250,000 and IHG with 185,000.

“In all affected tenant dumps, the leaked fields consistently included core corporate directory attributes,” says Hudson Rock.

Advertising. Scroll to continue reading.

Exfiltrated information includes employee names, corporate email addresses, addresses, phone numbers, employee IDs, job titles, manager details, user group memberships, service accounts, high-privilege account records, and more.

“The disclosure of service accounts and names of global administrators is particularly worrisome, as it provides a direct roadmap for subsequent social engineering, phishing, or targeted privilege escalation attacks against these organizations,” notes Hudson Rock.

According to the company, credentials compromised in a targeted phishing campaign were likely used to exfiltrate the data. Not only did Hudson Rock identify stolen credentials associated with most of the affected organizations, but the victimology suggested a targeted attack.

“The campaign affects multiple global enterprises in IT services, hospitality, telecommunications, retail and logistics,” the company notes.

Hudson Rock also points out that stolen data poses an immediate threat to victim organizations because it allows attackers to map internal reporting structures and high-value targets, and enables them to launch convincing phishing and business email compromise (BEC) attacks.

Related: 1.6 million likely to be affected by RingCentral data breach

Related: 14,000 Trezor customers affected by ShipMonk data breach

Related: Trivi, not LiteLLM, is behind the compromise with 2,500 organizations

Related: Massive password spraying campaign targeting the Azure CLI

Leave a Reply

Your email address will not be published. Required fields are marked *