Breaking
SecurityDeveloping Story

Azure Tenant Data Theft Hits Fortune 500 Firms

A threat actor is selling millions of records allegedly stolen from Azure tenants of major companies.

··2 hours ago·2 min read
a golden padlock sitting on top of a keyboard
Photo by Towfiqu barbhuiya on Unsplash

A cybercriminal going by the moniker 'TheHatman' is hawking datasets that purportedly contain sensitive employee information from the Azure cloud environments of several Fortune 500 corporations. The listings, which have come to light via threat intelligence firm Hudson Rock, suggest a broad and targeted operation that may have compromised the internal directories of some of the world's most recognizable brands.

The Scope of the Alleged Breach

According to Hudson Rock's analysis, the threat actor claims to have exfiltrated data directly from Azure and Entra ID tenants using leaked credentials. The affected organizations include McDonald's Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. The sheer number of records involved is staggering.

Inside the Exfiltrated Data

The dumped datasets appear to contain internal employee directories. Hudson Rock says that based on the identified email addresses and field names matching Azure directory exports, the data appears legitimate. The McDonald's dump is the largest, containing over 1.7 million records, followed by the TCS dataset with 800,000 records, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000.

What's in the Leaked Fields

"Across all the affected tenant dumps, the leaked fields consistently include foundational corporate directory attributes," Hudson Rock says. The exfiltrated information includes employee names, corporate email addresses, addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, and highly privileged account records.

The Threat of Privileged Account Exposure

Hudson Rock highlights that the inclusion of service accounts and global admin names is particularly concerning. "The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations," Hudson Rock notes.

How the Attack Likely Unfolded

According to the company, credentials compromised in a targeted infostealer campaign were likely used to exfiltrate the data. Hudson Rock identified stolen credentials linked to most of the affected organizations, and the victimology suggests a targeted attack, not an opportunistic one. "The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics," the company notes.

Immediate Threats to Victim Organizations

Hudson Rock points out that the stolen data poses an immediate threat. Attackers can map internal reporting structures and identify high-value targets, enabling them to launch convincing spear-phishing and business email compromise (BEC) attacks. The data provides a treasure trove for further intrusion attempts.

Why This Matters for Enterprises

The incident underscores the risks associated with cloud-based identity and access management. Even with robust security controls, a single compromised credential can lead to the exfiltration of vast amounts of sensitive data. For the affected Fortune 500 companies, this could mean a prolonged period of heightened phishing risk and potential follow-on attacks. The fact that the data is already being sold publicly increases the likelihood that other malicious actors will acquire it, amplifying the threat beyond the initial breach.

#cloud security#data breach#azure#hudson rock#thehatman#fortune 500

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories