A sprawling Azure data exfiltration campaign is unfolding across the dark web, with a threat actor systematically selling off internal employee directories stolen from some of the world’s largest corporations.
The seller, operating under the alias “TheHatman,” claims to have pulled these records directly from victim organizations’ Azure and Entra tenants using compromised credentials, and the volume of data on offer is staggering.
Over the past week, TheHatman has flooded underground forums with listings for at least nine Fortune 500-level enterprises spanning IT services, hospitality, telecommunications, retail, and logistics.
McDonald’s Corporation tops the list with more than 1.7 million exposed records, followed by Tata Consultancy Services at roughly 800,000, Vodafone at approximately 425,000, and HCL Technologies at around 250,000.

Additional victims include InterContinental Hotels Group with about 185,000 records, Kyndryl with 170,000, Gap Inc. with 80,000, Hexaware Technologies with 20,000, and Wyndham Hotels with 9,000.
Azure Credential Theft Campaign
Hudson Rock researchers who reviewed sample datasets say the information appears highly credible, citing corporate email domains and field structures that align precisely with standard Azure directory exports.
The leaked datasets consistently follow the same template. Core fields include full names, corporate email addresses drawn from both active company domains and tenant-specific onmicrosoft.com structures, phone numbers, and physical addresses. Beyond basic contact details, the dumps expose organizational data such as employee IDs, job titles, departments, manager assignments, and direct reports.

Most alarming is the inclusion of access and group mapping information, including service account details and, in some cases, listings of Global Administrator accounts. Exposing that kind of privileged account data hands attackers a ready-made blueprint for spear-phishing, social engineering, and targeted privilege escalation.
What remains unclear is exactly how the intrusions occurred. TheHatman has repeatedly said the data was obtained “using compromised credentials,” but the precise entry point is still unconfirmed, according to Hudson Rock.
Possible explanations include infostealer malware harvesting session tokens directly from employee machines, phishing campaigns that yielded administrative-level access, tenants lacking strict multi-factor authentication enforcement, or abuse of a third-party API or integration with overly broad read permissions. The speed and consistency of the dumps point to a systematic, likely automated, process once initial footholds were established.
Adding weight to the infostealer theory, researchers at Hudson Rock say they identified compromised Azure credentials tied to infostealer infections linked to most of the affected companies, including machines traced to employees at TCS, Gap Inc., HCL Technologies, and Kyndryl.
One compromised device reportedly contained dozens of corporate credentials and hundreds of sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account. The fact that only massive multinational firms appear in this campaign, rather than a broad cross-section of smaller businesses, suggests targeted exploitation of stolen credentials rather than an underlying Azure platform vulnerability.
The real-world risk here goes well beyond the initial leak. Threat actors routinely weaponize structured directory data like this to run convincing business email compromise and spear-phishing operations, using accurate reporting lines and job titles to impersonate managers or IT staff and trick employees into approving fraudulent transfers or surrendering MFA codes.
The exposure of service accounts and administrator names also functions as a targeting map for initial access brokers and ransomware crews looking for the fastest route into critical infrastructure.
Organizations should treat this incident as a reminder that credential hygiene, not just perimeter defense, now determines exposure. Continuous monitoring for infostealer-compromised credentials, enforced MFA across all tenant portals, and tighter scrutiny of third-party API permissions are essential steps to close the gap before attackers exploit it.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
