A large-scale Azure data exfiltration campaign is unfolding across underground forums, where a threat actor using the alias “TheHatman” is allegedly selling internal employee directories taken from major multinational organizations.
The actor claims the data was extracted from compromised Microsoft Azure and Entra ID tenants using stolen corporate credentials, exposing a serious identity-security risk for enterprises reliant on cloud directory services.
The listings reportedly cover at least nine Fortune 500-scale companies in technology services, hospitality, telecommunications, retail, and logistics. McDonald’s Corporation is said to account for the largest dataset, containing more than 1.7 million employee records.
Hackers Use Compromised Azure Credentials
Tata Consultancy Services reportedly follows with about 800,000 records, while Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels also appear in the alleged sales posts.
Researchers at Hudson Rock reviewed samples from the datasets and said the information appears credible. The records reportedly include corporate email domains, tenant-specific onmicrosoft.com addresses, and fields that closely resemble those in standard Azure directory exports.
Rather than exposing only names and email addresses, the dumps allegedly include phone numbers, physical addresses, employee IDs, job titles, departments, reporting relationships, manager assignments, and direct reports.
The most sensitive component is the reported inclusion of group memberships, service account information, access mappings, and, in some instances, the names of Global Administrator accounts.
Such information can provide criminals with a detailed blueprint of a target’s identity environment.
Attackers can use it to identify privileged users, map organizational reporting chains, and craft phishing messages that convincingly impersonate executives, HR staff, help desk personnel, or IT administrators. The initial access method remains unconfirmed.
TheHatman has stated only that compromised credentials were used. Possible sources include infostealer infections that captured browser passwords and session cookies, phishing campaigns that harvested credentials or MFA codes, weak enforcement of multi-factor authentication, and third-party applications granted excessive Microsoft Graph or directory read permissions.
Hudson Rock researchers reportedly identified compromised Azure credentials linked to infostealer activity at several companies, including TCS, Gap Inc., HCL Technologies, and Kyndryl.
One affected endpoint allegedly held dozens of corporate credentials and hundreds of sensitive session cookies, including access associated with a Kyndryl Azure Active Directory account.

This evidence strengthens the possibility that stolen identity material, rather than an Azure platform flaw, enabled the activity. The consequences may extend far beyond the publication of employee data.
Accurate directory information can support business email compromise, targeted social engineering, account takeover, and ransomware operations.
Privileged-account and service-account intelligence is especially useful to initial-access brokers seeking a rapid route into sensitive systems.
Organizations should immediately investigate unusual sign-ins, bulk directory enumeration, unfamiliar OAuth applications, and anomalous token activity.
Enforcing phishing-resistant MFA, revoking potentially stolen sessions, rotating exposed credentials, reviewing administrative roles, and restricting third-party API permissions are essential.
The campaign demonstrates that protecting cloud identities is now as important as defending endpoints and networks. A single compromised credential can expose an enterprise’s internal structure and give attackers the intelligence needed for a damaging intrusion.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR
Click Here For The Original Source.
