Hacker claims 3.6 million Azure account records stolen from major companies

A massive data breach affecting multiple major companies has come to light, with a threat actor claiming to have stolen over 3.6 million Azure account records from Fortune 500 organizations. The alleged hacker, known as “TheHatman,” is selling these databases on the dark web, which could potentially put millions of employees at risk.

According to TheHatman’s posts on various hacking forums, the breach involved compromised credentials used to gain access to Microsoft Azure infrastructure. The data dumps allegedly contain sensitive information such as names, employee IDs, email addresses, job titles, phone numbers, postal addresses, and service accounts. For example, a recent post claimed to have 1.7 million employee records from McDonald’s, downloaded directly from Azure Tenant using compromised credentials.

One of the companies affected is Tata Consultancy Services (TCS), which has denied any breach despite TheHatman’s claims. TCS stated that the information appears to be at least four years old and includes only basic employee data. The company added that it has strong safeguards in place against password spray attacks, such as Multi-Factor Authentication (MFA) fatigue, which is allegedly used by TheHatman.

Other companies affected include Gap Inc., Vodafone, HCL Technologies, InterContinental Hotels, Wyndham Hotels, Hexaware, and Kyndryl.com. While some of these companies have denied any breach, others are still investigating the claims. A spokesperson for Gap Inc. stated that the company found no evidence of a breach and that the advertised data is not sensitive in nature and “dated back to several years ago.”

The data dumps contain what’s known as “foundational corporate directory attributes,” which could be used for social engineering and spearphishing attacks. Cybersecurity firm Hudson Rock analyzed the leaks and confirmed that they are authentic, but the access vector and exfiltration method remain unknown.

This breach highlights the risks associated with compromised credentials and the importance of robust security measures to prevent such attacks. It also underscores the need for companies to regularly review their defenses and stay up-to-date with the latest threat intelligence.

As a result of this incident, it’s essential for employees to be vigilant about phishing attempts and other social engineering tactics that could exploit sensitive information. Companies should also prioritize regular password rotations, two-factor authentication, and ongoing security awareness training to minimize the risk of such breaches in the future.

For individuals who may have been affected by this breach, it’s crucial to monitor their email accounts and financial statements for any suspicious activity. If you suspect your data has been compromised, report it to the relevant authorities immediately and take steps to protect yourself from potential identity theft or other malicious activities.


Source: Bleeping Computer — 2026-08-17