Threat actor advertises alleged data from nine corporate Azure tenants
A threat actor using the name “TheHatman” is offering millions of employee records allegedly taken from Microsoft Azure environments belonging to nine large organizations, according to threat-intellig...
A threat actor using the name “TheHatman” is offering millions of employee records allegedly taken from Microsoft Azure environments belonging to nine large organizations, according to threat-intelligence company Hudson Rock.
The companies named in the report include McDonald’s, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, IHG Hotels & Resorts, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts. The alleged dataset includes approximately 1.7 million McDonald’s records, 800,000 linked to TCS, 425,000 associated with Vodafone, and 250,000 attributed to HCL Technologies.
Hudson Rock said samples appeared highly likely to be genuine, based partly on corporate email addresses and directory structures consistent with Microsoft cloud identity exports. The information reportedly extends beyond names and business email addresses. Samples allegedly contain telephone numbers, physical addresses, employee identifiers, job titles, departments, office locations, reporting relationships, group memberships, and service-account information.
Some records are also said to indicate which accounts have Global Administrator privileges. Such details could help criminals identify high-value targets for phishing or further account compromise, even if the advertised data does not include passwords.
The initial access method has not been confirmed. The threat actor has reportedly cited compromised credentials, password spraying, and multifactor-authentication fatigue. Hudson Rock also identified other possible routes, including credentials or session cookies stolen by infostealer malware, phishing, weak MFA protections, and overly broad permissions granted to third-party applications.
Hudson Rock said its own database contained stolen Microsoft cloud credentials connected with most of the named companies, but it could not establish that those credentials were used by TheHatman. The company assessed that targeted infections or credential theft were more plausible explanations than a broad Azure vulnerability, noting that the alleged victims are predominantly very large enterprises.
TCS told India’s stock exchange that it had investigated threat-intelligence alerts about possible employee-information exposure and found no credible evidence of a breach affecting its systems or customer environments. The company said the material appeared to be more than four years old and limited to basic employee information. It added that safeguards against password spraying and MFA fatigue had been in place for more than two years and remained effective based on its review.
The authenticity and source of the full dataset remain unverified, and inquiries to the other organizations and Microsoft were still awaiting responses.
