Fortune 500 Companies Hit in Azure Data Theft Campaign

A sophisticated threat actor, known by the moniker “TheHatman”, has been selling millions of records allegedly stolen directly from the Azure tenants of several Fortune 500 organizations. The compromised data includes sensitive information about employees, such as names, email addresses, phone numbers, and job titles.

According to Hudson Rock, a company that specializes in tracking threat actor activities, the data was exfiltrated using leaked credentials from Azure/Entra instances. The affected companies include well-known brands like McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.

The stolen data contains internal employee directories that appear to be legitimate, based on the identified email addresses and field names that match Azure directory exports. The exfiltrated information includes employee names, corporate email addresses, addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, highly privileged account records, and more.

The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations. Hudson Rock notes that the stolen data poses an immediate threat to the victim organizations, allowing attackers to map internal reporting structures and high-value targets.

The campaign appears to be a targeted attack, with credentials compromised in a previous infostealer campaign likely used to exfiltrate the data. The affected companies span multiple industries, including IT services, hospitality, telecommunications, retail, and logistics. With millions of records stolen, the potential for social engineering attacks, spear-phishing, or business email compromise (BEC) is high.

This incident highlights the importance of secure credential management and monitoring Azure/Entra instances for suspicious activity. Organizations must ensure that their employees are aware of the risks associated with compromised credentials and take steps to prevent such attacks in the future. It’s also essential for companies to regularly review their Azure/Entra security settings and monitor for any potential vulnerabilities.

As a practical takeaway, organizations should prioritize secure credential management and implement robust monitoring systems to detect suspicious activity on their Azure/Entra instances. Regularly reviewing Azure/Entra security settings and staying up-to-date with the latest security patches is also crucial to preventing such attacks. By taking these steps, companies can reduce their risk of being targeted by sophisticated threat actors like TheHatman.


Source: SecurityWeek — 2026-08-17