News

Fortune 500 companies hit in a mass Azure data-theft campaign

A threat actor called TheHatman is selling data tied to major companies' Azure tenants. Hudson Rock traced it to compromised credentials, but the scope and the entry point are both disputed.

Fortune 500 companies hit in a mass Azure data-theft campaign

A threat actor operating as TheHatman is selling data linked to the Microsoft Azure tenants of several large companies. The security firm Hudson Rock, which documented the campaign, ties the exposure to compromised credentials rather than a flaw in Azure itself. The scope and the exact entry point are both disputed, so it is worth separating what is claimed from what is confirmed.

TheHatman listing McDonald's data for sale

Who is named

The seller's victim list is long and full of well-known names. Reporting from SecurityWeek and Hudson Rock cites McDonald's, Vodafone, Tata Consultancy Services (around 800,000 records), HCL, IHG, Kyndryl, Gap, Hexaware, and Wyndham. The most-cited single figure is the roughly 1.7 million McDonald's employee records that surfaced on a leak forum, reported by Security Affairs and Cybernews, while BleepingComputer notes the seller's overall claim of about 3.6 million Azure account records. Every one of those totals comes from the seller and is unverified.

The pushback

Not every named company accepts the story. Tata Consultancy Services and Gap have both pushed back, saying the data on offer looks old and that they have found no evidence of a live breach of their Azure tenants. A record showing up in a dump is not the same thing as an attacker sitting inside a current environment. Until an affected company confirms an active intrusion, the safest reading is that this is a resale of previously harvested data of uncertain age and origin.

How the credentials were obtained

This is the part to be careful with. Hudson Rock says the exact vector is not confirmed, and points toward infostealer malware, the kind that quietly harvests saved logins and session tokens from infected machines and feeds them into criminal markets. That is a different problem from a single exploited vulnerability. It can spread the exposure across many employees and contractors at many companies, without any one of them being obviously breached.

What this is not, at least on the current evidence, is a confirmed phishing or multi-factor-bypass operation. Those are plausible ways credentials leak, but nobody has tied them to this specific case, so treat any single named vector as speculation for now.

What to check

The story is unsettled, but the hygiene it points to is not controversial:

  • Sign-in logs. Review your Azure and Entra ID logs for logins from new locations, impossible-travel patterns, and unfamiliar devices. A well-tuned SIEM makes anomalies far easier to spot.
  • Credential exposure. Assume some employee logins are already circulating, and force resets plus token revocation for anyone who turns up in an infostealer feed.
  • Third parties. Several of the named firms are IT service providers, so review contractor and vendor access, not just your own staff. If you are weighing tooling, our roundup of the top AI cybersecurity companies is a place to start.
  • AI and identity. As more teams wire AI tools into daily work, the identity layer guarding company data matters more, not less. Our guide on using AI at work covers the workflow side, and prompt injection is worth watching as those tools gain access to internal systems.

The takeaway

Right now this looks less like a fresh mass breach of Azure and more like a large, loudly advertised collection of enterprise credentials and records of uncertain age, some of which the named companies dispute. The platform is not the story. Credential exposure is, and the response is identity hygiene rather than any single patch.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free