Fortune 500 Companies Hit in Azure Data Theft Campaign

A massive data theft campaign has targeted several Fortune 500 companies, exposing millions of sensitive records that could be used in sophisticated social engineering attacks. The threat actor, known as “TheHatman,” claims to have stolen over 5 million records from the Azure tenants of prominent brands like McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, and others.

According to security experts at Hudson Rock, the data was likely exfiltrated using leaked credentials, which were compromised in a targeted infostealer campaign. The stolen information includes employee names, corporate email addresses, addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, and highly privileged account records.

The affected organizations span various industries, including IT services, hospitality, telecommunications, retail, and logistics. The scope of the attack is significant, with over 1.7 million records stolen from McDonald’s alone, followed by 800,000 records from TCS, and hundreds of thousands more from Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.

The stolen data poses an immediate threat to the victim organizations, as it allows attackers to map internal reporting structures and high-value targets. This information can be used to launch convincing spear-phishing and business email compromise (BEC) attacks, potentially leading to further exploitation of vulnerabilities within these companies.

Hudson Rock notes that the exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering or targeted privilege escalation attacks. The security experts emphasize that the campaign’s impact is not limited to the stolen data itself but also represents a significant vulnerability in the affected organizations’ Azure environments.

This incident highlights the importance of robust password management, regular credential rotation, and strict access controls within cloud environments. Organizations should take immediate action to review their Azure configurations, update credentials, and implement additional security measures to prevent similar attacks in the future.


Source: SecurityWeek — 2026-08-17