A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS). Over the past week, the threat actor has posted a string of large internal employee directories on cybercrime forums. In addition, the alleged victims include HCL Technologies, InterContinental Hotels Group (IHG), Gap Inc., Hexaware Technologies, and Wyndham Hotels.
The volume of data on offer is large, with McDonald’s topping the list with an estimated 1.7 million records. TCS is recorded at around 800,000, while Vodafone is at roughly 425,000, and HCL is at about 250,000. IHG, Kyndryl, Gap, Hexaware, and Wyndham round out the rest, with counts ranging from several thousand to over 170,000 records apiece.
Hudson Rock researchers examined samples of the leaked data and found corporate email addresses and field names consistent with a standard Azure directory export, indicating that the material is likely authentic.
“While the data is highly likely authentic, it is not conclusive how this campaign is being carried out,” Hudson Rock said.
“However, the exact intrusion vector remains unknown. This mass exfiltration could be the result of active Infostealer infections compromising employee session tokens, highly successful phishing campaigns yielding administrative access, a lack of strict Multi-Factor Authentication (MFA) on specific tenant portals, or potentially an abuse of a third-party API/Integration that had excessive read privileges across multiple environments. The sheer scale and speed of these dumps suggest a systematic, automated approach once initial access is achieved,” they added.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




