Hacker claims 3.6 million Azure account records stolen from major companies

A massive cache of sensitive employee data has been put up for sale on the dark web by a threat actor claiming to have stolen 3.6 million records from major companies that use Microsoft Azure infrastructure. The attacker, known as “TheHatman,” claims to have accessed these records using compromised credentials, exploiting vulnerabilities in Azure’s security.

Multiple Fortune 500 companies are said to be affected, including McDonald’s, Gap Inc., Vodafone, and Tata Consultancy Services (TCS). The data allegedly includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records. In some cases, the stolen data appears to be several years old and may not be highly sensitive.

One of the companies mentioned, TCS, has issued a statement saying that it investigated the alleged breach and found no credible evidence of a security incident. The company claims that its systems have had strong safeguards in place against password spraying and MFA fatigue for over two years. It’s worth noting that even if the data is old or not highly sensitive, having it stolen can still cause significant harm to affected employees.

TheHatman has been advertising these data dumps on various dark web forums since July 31st. Each dump includes a sample database with verified data, allowing potential buyers to test its authenticity before purchasing. Cybercrime intelligence company Hudson Rock analyzed the leaks and confirmed that they contain foundational corporate directory attributes and clear data structures, including service accounts and global administrator names.

This type of breach is particularly concerning because it highlights the importance of robust password management and Multi-Factor Authentication (MFA) practices. Attackers can easily use compromised credentials to gain access to sensitive systems, and once inside, they often have a high success rate in carrying out malicious activities. In fact, studies show that once attackers obtain valid credentials, only 37% of their actions are blocked by security measures.

The affected companies should take immediate action to review their Azure infrastructure and ensure that all necessary security patches are applied. Employees whose data may have been compromised should be notified and provided with guidance on how to protect themselves from potential social engineering and spearphishing attacks. As a general takeaway, it’s essential for organizations to prioritize strong password management, regular security audits, and employee education on cybersecurity best practices to prevent similar breaches in the future.


Source: Bleeping Computer — 2026-08-17