TheHatman Just Pulled 3.6 Million Azure Employee Records From Fortune 500 Companies

Over the past two weeks, a threat actor calling himself "TheHatman" has been flooding cybercrime forums with massive internal employee directories pulled directly from the Azure tenants of some of the biggest companies in the world. McDonald's tops the list with 1.7 million records, followed by Tata Consultancy Services at 800,000, Vodafone at 425,000, HCL Technologies at 250,000, InterContinental Hotels Group at 185,000, and Kyndryl at 170,000. The full haul comes to 3.64 million records — names, corporate emails, phone numbers, addresses, job titles, employee IDs, manager details, user group memberships, service accounts, and even Global Administrator listings.

What makes this interesting isn't just the scale, but the access vector. The data was exfiltrated from Azure/Entra portals using leaked credentials — not a zero-day in Azure itself, but a targeted campaign where infostealer infections gave TheHatman valid session tokens across multiple organizations. Hudson Rock found compromised Azure credentials linked to most of the affected companies, confirming the attack was driven by targeted infostealer malware rather than a platform-wide vulnerability. The attack reportedly used password spray and MFA fatigue to gain initial access, and once inside, the data was dumped in bulk using standard Azure Graph API calls — the same tool half the IT world already uses for directory queries.

Source article image
Source image 1

The real threat here isn't the directory dump itself — those fields are already public-adjacent. It's what you can do once you know who reports to whom, which accounts are service accounts versus humans, and what the Global Admins look like. Hudson Rock points out that this data gives attackers a direct roadmap for spear-phishing, Business Email Compromise, and privilege escalation. Several of the affected companies — Gap, TCS — say the data is at least four

Source article image
Source image 2
years old and non-sensitive, but McDonald's and Vodafone haven't publicly commented yet. If you're running Azure at enterprise scale and your employees haven't rotated credentials in a while, you might want to check whether any infostealer on their machines has a cookie for login.microsoftonline.com.

Sources

  • BleepingComputer: "Hacker claims 3.6 million Azure account records stolen from major companies" — https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
  • SecurityWeek: "Fortune 500 Companies Hit in Azure Data Theft Campaign" — https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/
  • Hudson Rock/InfoStealers: "Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records" — https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/

Comments

Popular posts from this blog

AI Is Starting to Feel Less Like a Gadget and More Like Infrastructure

When Two AI Bots Finally Learned to Talk in Discord

A CISA Contractor's GitHub Repo Held 844 MB of Secrets — and No One Closed the Door