Azure Tenant Data Theft Hits Fortune 500 Firms
A threat actor is selling millions of records allegedly stolen from Azure tenants of major companies.
A cybercriminal going by the moniker 'TheHatman' is hawking datasets that purportedly contain sensitive employee information from the Azure cloud environments of several Fortune 500 corporations. The listings, which have come to light via threat intelligence firm Hudson Rock, suggest a broad and targeted operation that may have compromised the internal directories of some of the world's most recognizable brands.
The Scope of the Alleged Breach
According to Hudson Rock's analysis, the threat actor claims to have exfiltrated data directly from Azure and Entra ID tenants using leaked credentials. The affected organizations include McDonald's Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. The sheer number of records involved is staggering.
Inside the Exfiltrated Data
The dumped datasets appear to contain internal employee directories. Hudson Rock says that based on the identified email addresses and field names matching Azure directory exports, the data appears legitimate. The McDonald's dump is the largest, containing over 1.7 million records, followed by the TCS dataset with 800,000 records, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000.
What's in the Leaked Fields
"Across all the affected tenant dumps, the leaked fields consistently include foundational corporate directory attributes," Hudson Rock says. The exfiltrated information includes employee names, corporate email addresses, addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, and highly privileged account records.
The Threat of Privileged Account Exposure
Hudson Rock highlights that the inclusion of service accounts and global admin names is particularly concerning. "The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations," Hudson Rock notes.
How the Attack Likely Unfolded
According to the company, credentials compromised in a targeted infostealer campaign were likely used to exfiltrate the data. Hudson Rock identified stolen credentials linked to most of the affected organizations, and the victimology suggests a targeted attack, not an opportunistic one. "The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics," the company notes.
Immediate Threats to Victim Organizations
Hudson Rock points out that the stolen data poses an immediate threat. Attackers can map internal reporting structures and identify high-value targets, enabling them to launch convincing spear-phishing and business email compromise (BEC) attacks. The data provides a treasure trove for further intrusion attempts.
Why This Matters for Enterprises
The incident underscores the risks associated with cloud-based identity and access management. Even with robust security controls, a single compromised credential can lead to the exfiltration of vast amounts of sensitive data. For the affected Fortune 500 companies, this could mean a prolonged period of heightened phishing risk and potential follow-on attacks. The fact that the data is already being sold publicly increases the likelihood that other malicious actors will acquire it, amplifying the threat beyond the initial breach.
Sources
- SecurityWeek Original source
Continue Reading
Threema DDoS attacks expose mitigation limits
Swiss messaging firm Threema faced sustained DDoS attacks this week, with changing tactics challenging defenses.
Why 2,500-Org Breach Wasn't What It Seemed
SOCRadar says most orgs hit in LiteLLM attack were earlier Trivy victims, not LiteLLM.
Salesforce and ServiceNow attacks expose new API risks
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.