A threat actor is advertising an Azure employee data breach campaign that allegedly netted 3.64 million records across nine major organisations, with McDonald’s, Tata Consultancy Services, and Vodafone among the named targets. The seller, operating under the alias ‘TheHatman’, began posting the alleged data dumps on 31 July and claims to have extracted the records directly from victims’ Microsoft Azure tenants using compromised credentials.

The posts, active between 31 July and 16 August, offer separate databases for each organisation, each accompanied by a sample file for prospective buyers to verify the contents. The claimed data types are broadly consistent across targets: full names, email addresses, job titles, phone numbers, and postal addresses, with some dumps also listing employee IDs, service accounts, and tenant-specific administrator records.

What the Azure Employee Data Breach Claims Involve

The largest alleged haul concerns McDonald’s, where TheHatman claims to hold more than 1.7 million internal employee records. ‘I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,’ the post reads. The Tata Consultancy Services entry is the second largest, at more than 800,000 records, described in identical language. Other organisations listed include Vodafone (425,000-plus records), Gap Inc. (80,000-plus), HCL Technologies (250,000-plus), InterContinental Hotels (185,000-plus), Kyndryl (170,000-plus), Hexaware (20,000-plus), and Wyndham Hotels (9,000-plus).

TheHatman claims the access vector was a combination of password spraying and MFA (multi-factor authentication) fatigue attacks, techniques that bypass authentication controls by either guessing commonly used passwords at scale or bombarding users with repeated MFA prompts until one is accidentally approved.

Company Responses and the Hudson Rock Assessment

Two of the named companies have so far pushed back on the claims. In a notification to the National Stock Exchange of India, Tata said it investigated the alleged breach and found no ‘credible evidence of a breach of TCS systems or customer environments.’ The company added that the details ‘appear to be at least four years old and include only basic employee information,’ and stated that it has had ‘strong safeguards in place against such techniques for more than two years,’ having reviewed those defences and found them effective.

Gap Inc. reached a similar conclusion. A Gap spokesperson told BleepingComputer, which first reported the campaign, that a preliminary investigation found the data ‘limited in scope, non-sensitive and dated back to several years ago,’ with no evidence that corporate systems had been compromised. The remaining companies had not responded to BleepingComputer’s requests for comment by the time of publication.

The independent picture from cybercrime intelligence company Hudson Rock is somewhat more troubling. The firm analysed the leaked samples and confirmed they contain what it described as ‘foundational corporate directory attributes’ with a clear data structure, including active domains and tenant-specific .onmicrosoft.com entries. Hudson Rock also noted that the dumps include service accounts and the names of global administrators, the kind of information that could give attackers useful footholds for social engineering and spearphishing campaigns, even if the underlying employee contact details turn out to be stale.

That said, Hudson Rock’s assessment stops short of full confirmation. The firm said it has high confidence that the data is authentic, but acknowledged that the access vector and exfiltration method remain unknown. BleepingComputer said it had not been able to independently verify the data’s authenticity.

The episode sits inside a broader pattern: once a threat actor holds valid credentials, conventional prevention controls become considerably less reliable. Whether the records are fresh or years old, the presence of administrator account names and service account details in the samples means the data carries a longer tail of potential misuse than a straightforward employee directory leak would suggest. Tata and Gap have both said their own investigations found no current exposure; none of the other seven named organisations have yet said the same.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version