Crook hawks millions of records allegedly plundered from corporate Azure tenants

Pradeep Veeraballe··1 min read
securityazuredata-breachneeds-rewrite
A digital breach with a silhouette of a person accessing data
openai.comtheregister.comsecurityweek.comtheregister.com

A threat actor, using the moniker 'TheHatman', is selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations, including McDonald's, Vodafone, TCS, Kyndryl, and others. According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials.

A depiction of a digital breach with a silhouette of a person accessing data;

Affected Companies

The affected companies include McDonald's, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.

Data Details

The leaked data contains internal employee directories that appear legitimate, based on the identified email addresses and field names that match Azure directory exports. The McDonald's dump is the largest, containing over 1.7 million records, followed by the TCS dataset, with 800,000 records, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000.

Response and Investigation

Microsoft has not yet commented on the incident. Security researchers at Hudson Rock have identified the threat actor and are working to verify the authenticity of the stolen data.

"Across all the affected tenant dumps, the leaked fields consistently include foundational corporate directory attributes," Hudson Rock says.

Sources

Sources

Keep reading

Stay on top of tech and AI

Subscribe wiring is coming soon. For now, follow the daily news feed or connect on LinkedIn for updates.

Read latest newsConnect on LinkedIn