Skip to main content

Threat Actor Claims 3.6 Million Azure Account Records Stolen

3 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • A threat actor claims to have stolen 3.6 million employee records from multiple Fortune 500 companies using compromised credentials.
  • The breaches allegedly affect corporate Microsoft Azure tenants belonging to organizations including McDonald's, Gap Inc., and Vodafone.
  • Defenders must prioritize auditing Azure tenant access, enforcing phishing-resistant MFA, and monitoring service accounts for unauthorized activity.

Advertisement

Overview of Azure Tenant Data Dumps

A threat actor operating under the alias “TheHatman” has advertised employee databases allegedly stolen from the Microsoft Azure infrastructure of several major organizations. According to details reported by BleepingComputer, the campaign began on July 31st and targets multiple Fortune 500 companies, including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group (IHG), and Kyndryl.

In total, the threat actor claims possession of 3.64 million records. The largest single dump, advertised on a Sunday, allegedly contains 1.7 million employee records from McDonald’s. The second-largest set comprises over 800,000 employee records attributed to Tata Consultancy Services. The leaked information reportedly includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, and service account identifiers.

Technical Analysis and Exfiltrated Data

Cybercrime intelligence firm Hudson Rock analyzed samples provided by the threat actor and confirmed that the files contain foundational corporate directory attributes. The data structure includes active domains and tenant-specific .onmicrosoft.com naming conventions. Furthermore, the dumps expose service accounts and global administrator names.

While the exact initial access vector remains unconfirmed, the threat actor asserted the use of password spraying and multi-factor authentication (MFA) fatigue techniques. However, several targeted organizations have contested the scope and current impact of the claims:

  • Tata Consultancy Services: Investigated the claims and found no credible evidence of a modern system breach, stating the data appears to be at least four years old and limited to basic directory info.
  • Gap Inc.: Reported that preliminary investigations indicate the data is limited in scope, non-sensitive, several years old, and does not reflect a current corporate network compromise.

Despite pushback regarding the freshness of the records, security analysts warn that exposure of active .onmicrosoft.com structures and administrator names creates significant risks for downstream operations.

Downstream Risks: Social Engineering and Spearphishing

The presence of service accounts, internal email addresses, and structural Azure tenant metadata in unauthorized hands poses distinct tactical risks. Attackers frequently weaponize directory dumps to conduct targeted social engineering campaigns. When threat actors possess accurate organizational charts, valid email formats, and known service account designations, business email compromise (BEC) and sophisticated spearphishing operations become significantly easier to execute against third-party vendors and internal staff.

Actionable Recommendations and Mitigations

Organizations must treat compromised cloud directory data as a persistent risk indicator. Security teams should implement the following defensive measures:

  • Audit Azure Tenant Configurations: Review global administrator roles and service account permissions regularly to ensure strict adherence to the principle of least privilege.
  • Enforce Phishing-Resistant MFA: Upgrade authentication mechanisms to FIDO2-based security keys or certificate-based authentication to neutralize MFA fatigue and prompt-bombing techniques.
  • Monitor Directory Enumeration: Implement anomaly detection for unusual Microsoft Entra ID (formerly Azure AD) querying behaviors that indicate reconnaissance or directory harvesting.

Related: SafePal Data Breach Exposes 39,798 Customer Order Details, Phishing Targets AI Service Users: Guard Your ChatGPT Accounts

Advertisement

Advertisement