A threat actor is claiming to have stolen and is now selling data allegedly taken directly from the Azure tenants of several Fortune 500 organizations, raising concerns over the security of enterprise cloud environments and the growing impact of credential theft. Operating under the alias “TheHatman”, the individual has reportedly listed millions of records for sale that are said to belong to major global companies, including McDonalds Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. According to the threat actor, the information was extracted from Azure and Microsoft Entra environments using leaked credentials, suggesting that compromised accounts may have provided direct access to corporate cloud directories.
Cybersecurity firm Hudson Rock has examined the leaked information and says the exposed datasets appear legitimate based on the structure of the records, identified email addresses, and field names that closely match Azure directory exports. Among the reported datasets, McDonalds is said to have the largest collection with more than 1.7 million records, followed by Tata Consultancy Services with approximately 800,000 records, Vodafone with 425,000 records, HCL Technologies with 250,000 records, and InterContinental Hotels Group with around 185,000 records. Hudson Rock notes that the leaked information consistently contains core corporate directory attributes across all affected organizations. These include employee names, corporate email addresses, office addresses, phone numbers, employee identification numbers, job titles, reporting manager details, user group memberships, service accounts, privileged administrative accounts, and other directory related information. The company warns that the presence of service accounts and global administrator details is particularly concerning because such information could provide attackers with valuable intelligence for future social engineering campaigns, spear phishing attempts, or privilege escalation attacks targeting enterprise networks.
According to Hudson Rock, the campaign was likely enabled through credentials previously compromised by an infostealer operation that specifically targeted enterprise users. The security company says it identified stolen credentials linked to most of the organizations whose data allegedly appeared in the leaked collections, while the pattern of affected victims also suggests a targeted campaign rather than random exposure. The incident spans multiple industries, including information technology services, hospitality, telecommunications, retail, and logistics, indicating that attackers may have deliberately focused on organizations with large cloud based infrastructures. The reported use of compromised Azure and Entra credentials also highlights the risks associated with stolen login information, particularly when accounts are granted access to enterprise identity management systems.
Hudson Rock further warns that the leaked corporate directory data could create immediate security risks for the affected organizations even if no additional systems were compromised. By gaining access to detailed employee information, organizational structures, and privileged account records, attackers may be able to identify high value targets, understand reporting hierarchies, and craft highly convincing spear phishing campaigns or business email compromise attacks. Such information can significantly improve the success rate of targeted cyberattacks because it allows threat actors to impersonate trusted employees or departments with greater accuracy. While the companies named in the alleged data theft have not publicly confirmed the claims at the time of reporting, the incident serves as another reminder of the importance of protecting enterprise credentials, monitoring cloud identities, and responding quickly to signs of account compromise to reduce the risk of unauthorized access to critical business systems.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.