teiss – News – Fortune 500 firms targeted in Azure campaign exposing 3.7 million employee records | #cybercrime | #infosec


A threat actor has dumped nearly 3.7 million employee records from several Fortune 500 companies, exposing vast internal directories on cybercrime forums following a major Azure data exfiltration campaign.

 

Recently, Hudson Rock reported that a cyber criminal operating under the moniker “The Hatman” flooded dark web forums with massive internal employee directories belonging to several Fortune 500 and major global companies, including McDonald’s Corporation, TCS (Tata Consultancy Services), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.

 

The actor claimed that these datasets were extracted directly from the organisations’ Azure tenants. According to the report, the extensive directories were allegedly obtained through compromised credentials used to access the organisations’ Azure/Entra portals.

 

The threat actor claims to possess approximately 3.64 million records in total. The latest breach, posted on Sunday, reportedly involves 1.7 million employee records from McDonald’s. According to TheHatman, the exposed data includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant-related account information.

 

 

 

“I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” the threat actor said. 

 

While TCS, in a notification to the National Stock Exchange of India, said it had investigated the alleged breach and found no credible evidence of a compromise affecting its systems or customer environments, the second-largest data dump advertised by the threat actor allegedly involves Tata Consultancy Services. The actor claims to have obtained more than 800,000 employee records from an Azure tenant, stating that the data was “downloaded directly from Azure Tenant using compromised credentials.”

 

In a statement shared with BleepingComputer, a Gap Inc. spokesperson said that the company found no evidence of a breach. The spokesperson also stated that the advertised data was not sensitive and dated back several years.

 

“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” the Gap Inc. representative said.

 

Hudson Rock said the leaked datasets contain extensive corporate directory data, including domains, .onmicrosoft.com structures, employee IDs, contact details, job titles, departments, and management information, while warning that exposed service accounts and global administrator names could enable targeted social engineering, spear-phishing, or privilege escalation attacks.





Click Here For The Original Source.

——————————————————–

..........

.

.