News

A seller is offering Azure data tied to Fortune 500 names, and two of them dispute it

A threat actor called TheHatman is advertising data linked to major companies' Azure tenants. Hudson Rock points to compromised credentials rather than an Azure flaw, the totals all come from the seller, and Tata Consultancy Services and Gap say the data looks old.

A seller is offering Azure data tied to Fortune 500 names, and two of them dispute it

A seller calling themselves TheHatman is advertising data they say came from the Microsoft Azure tenants of several large companies. The security firm Hudson Rock, which documented the campaign, ties the exposure to compromised credentials rather than a flaw in Azure itself. The scope and the entry point are both disputed.

TheHatman listing McDonald's data for sale

Reporting from SecurityWeek and Hudson Rock cites McDonald's, Vodafone, Tata Consultancy Services (around 800,000 records), HCL, IHG, Kyndryl, Gap, Hexaware and Wyndham. The most-cited single figure is the roughly 1.7 million McDonald's employee records that surfaced on a leak forum, reported by Security Affairs and Cybernews. BleepingComputer notes the seller's overall claim of about 3.6 million Azure account records.

Every one of those totals originates with the seller. None has been confirmed by a named company.

Tata Consultancy Services and Gap have both pushed back, saying the data on offer looks old and that they have found no evidence of a live breach of their Azure tenants. A record showing up in a dump is not the same thing as an attacker sitting inside a current environment. Until an affected company confirms an active intrusion, the supported reading is a resale of previously harvested data of uncertain age and origin.

Hudson Rock says the exact vector is not confirmed, and points toward infostealer malware, the kind that quietly harvests saved logins and session tokens from infected machines and feeds them into criminal markets. That is a different problem from a single exploited vulnerability. It spreads exposure across many employees and contractors at many companies, without any one of them being obviously breached. Several of the named firms are IT service providers.

Phishing and multi-factor-bypass operations are plausible ways credentials leak, but nobody has tied them to this specific case. On the evidence available, the listing looks less like a fresh mass breach of Azure and more like a large, loudly advertised collection of enterprise credentials and records of uncertain age, parts of which named companies dispute.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free