A seller is offering Azure data tied to Fortune 500 names, and two of them dispute it
A threat actor called TheHatman is advertising data linked to major companies' Azure tenants. Hudson Rock points to compromised credentials rather than an Azure flaw, the totals all come from the seller, and Tata Consultancy Services and Gap say the data looks old.

A threat actor operating as TheHatman is advertising data linked to the Microsoft Azure tenants of several large companies. The security firm Hudson Rock, which documented the campaign, ties the exposure to compromised credentials rather than a flaw in Azure itself. The scope and the entry point are both disputed, so it is worth separating what is claimed from what is confirmed.

Who is named
The seller's victim list is long and full of well-known names. Reporting from SecurityWeek and Hudson Rock cites McDonald's, Vodafone, Tata Consultancy Services (around 800,000 records), HCL, IHG, Kyndryl, Gap, Hexaware and Wyndham. The most-cited single figure is the roughly 1.7 million McDonald's employee records that surfaced on a leak forum, reported by Security Affairs and Cybernews, while BleepingComputer notes the seller's overall claim of about 3.6 million Azure account records.
Every one of those totals originates with the seller. None has been confirmed by a named company.
The pushback
Not every named company accepts the story. Tata Consultancy Services and Gap have both pushed back, saying the data on offer looks old and that they have found no evidence of a live breach of their Azure tenants.
A record showing up in a dump is not the same thing as an attacker sitting inside a current environment. Until an affected company confirms an active intrusion, the supported reading is that this is a resale of previously harvested data of uncertain age and origin.
How the credentials were obtained
This is the part to be careful with. Hudson Rock says the exact vector is not confirmed, and points toward infostealer malware, the kind that quietly harvests saved logins and session tokens from infected machines and feeds them into criminal markets. That is a different problem from a single exploited vulnerability. It spreads exposure across many employees and contractors at many companies, without any one of them being obviously breached.
What this is not, at least on current evidence, is a confirmed phishing or multi-factor-bypass operation. Those are plausible ways credentials leak, but nobody has tied them to this specific case, so treat any single named vector as speculation.
What to check
The story is unsettled. The hygiene it points to is not.
- Sign-in logs. Review your Azure and Entra ID logs for logins from new locations, impossible-travel patterns and unfamiliar devices. A well-tuned SIEM makes anomalies far easier to spot.
- Credential exposure. Assume some employee logins are already circulating, and force resets plus token revocation for anyone who turns up in an infostealer feed.
- Third parties. Several of the named firms are IT service providers, so review contractor and vendor access, not just your own staff.
- Age of the data. If you are named, the useful question is not whether records exist but when they were valid. Date the credentials against your own rotation history before you run an incident.
The takeaway
On the evidence available, this looks less like a fresh mass breach of Azure and more like a large, loudly advertised collection of enterprise credentials and records of uncertain age, parts of which named companies dispute. The platform is not the story. Credential exposure is, and the response is identity hygiene rather than any single patch. If your organization appears on the list, establish the age of the data first, because that determines whether you are running an incident or closing a stale exposure.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free