Data Breaches

Hacker Sells 3.6 Million Employee Records From Nine Companies’ Azure Tenants

A threat actor using the alias TheHatman is selling employee data pulled from the Microsoft Azure tenants of nine companies telling buyers every dump was obtained with compromised credentials rather than a platform flaw. The claimed total across all nine listings is 3.64 million records.

The newest and largest listing appeared on Sunday, an alleged 1.7 million employee records from McDonald’s Corporation, advertised in the forum post as an internal dump downloaded directly from Azure Tenant using compromised credentials.

McDonald’s Tops a List That Runs to Nine Companies

The other eight listings posted over the preceding two and a half weeks cover a mix of retail, telecoms, hospitality and IT services firms:

  • Tata Consultancy Services (TCS): 800,000+ records
  • Vodafone: 425,000+ records
  • HCL Technologies: 250,000+ records
  • InterContinental Hotels Group (IHG): 185,000+ records
  • Kyndryl: 170,000+ records
  • Gap Inc.: 80,000+ records
  • Hexaware Technologies: 20,000+ records
  • Wyndham Hotels: 9,000+ records

Each listing includes names, employee IDs, email addresses, job titles, phone numbers and postal addresses. The Kyndryl dump also includes service accounts and other tenant account records. TheHatman provided a sample database for every company so buyers can verify the data before paying.

TCS and Gap Say the Records Are Years Old

Tata Consultancy Services told the National Stock Exchange of India that it found no credible evidence of a breach of its systems or customer environments. The company said the leaked details are at least four years old, limited to basic employee information and that it has had safeguards against password spraying and MFA fatigue attacks in place for more than two years. TCS added that a review of its defences found them to still be effective.

A Gap Inc. spokesperson gave a similar account, the company found no evidence of a breach and the data on offer is limited in scope, not sensitive and several years old. The remaining seven companies had not responded by publication time.

Denying a breach is not the same as explaining where the data came from and neither company has done the latter.

Hudson Rock Blames Infostealers. Nobody Has Confirmed It.

Cybercrime intelligence firm Hudson Rock reviewed samples from the leaks and said the field structure including active domains and tenant-specific .onmicrosoft.com naming, matches genuine Azure directory exports. The firm rated the data as highly likely authentic but said the access vector and exfiltration method remain unconfirmed.

Hudson Rock also said it traced Azure credentials tied to infostealer infections at most of the named companies through its own threat intelligence platform and argued the pattern points to targeted credential theft rather than a flaw in Azure itself. That is a plausible read of a genuinely large campaign but Hudson Rock sells the exact monitoring product it says would catch this so treat the infostealer explanation as informed opinion, not a confirmed root cause until a named company confirms it independently.

The Fix Doesn’t Wait for a Confirmed Cause

Whatever the entry point turns out to be, the practical response is the same. Run Azure and Entra ID sign-in logs against known infostealer credential dumps not just against your own password reset history. Enforce phishing-resistant MFA on every account with directory read access since TCS’s own account shows that MFA fatigue attacks target the approval prompt not the password. Rotate credentials for service accounts and Global Administrator accounts specifically, the two account types Hudson Rock flagged as present in the leaked data and the two most useful to an attacker running a follow-up phishing campaign.

None of the nine companies named in the listings had issued a public breach notification as of 17 August. Employees at any of them should treat unexpected password-reset requests and MFA prompts with the same scepticism TCS says it already applies.

References

  1. Hacker Claims 3.6 Million Azure Account Records Stolen From Major Companies
  2. Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials
  3. Tata Consultancy Services Regulatory Filing on Alleged Azure Data Breach

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.