A threat actor is advertising millions of employee records allegedly stolen from the Microsoft Azure environments of several major companies after gaining access using compromised credentials.
Since July 31, a cybercriminal using the alias “TheHatman” has posted advertisements offering databases allegedly taken from organizations including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Wyndham Hotels, Hexaware and Kyndryl.
The threat actor claims to have obtained a total of around 3.64 million records, with the largest recently advertised database allegedly belonging to McDonald’s. The seller claims the McDonald’s database contains more than 1.7 million employee records that were downloaded directly from an Azure tenant using compromised credentials.
According to the threat actor, the McDonald’s data includes employee names, IDs, email addresses, job titles, phone numbers, postal addresses, service accounts and other tenant account information.
The second-largest database being advertised allegedly comes from Tata Consultancy Services, with more than 800,000 employee records. TheHatman claims this information was also downloaded directly from an Azure tenant using compromised credentials.
Tata Consultancy Services, however, has disputed the claims. In a notification to the National Stock Exchange of India, the company said its investigation found no credible evidence that its systems or customer environments had been breached. Tata said the information appeared to be at least four years old and contained only basic employee information.
The company also said the alleged attacker claimed to have used password spraying and MFA fatigue as the attack methods. Tata said it has had safeguards against those techniques in place for more than two years and that its review found those defenses remain effective.
Gap Inc. also said it found no evidence that its corporate systems had been compromised. A company spokesperson said the advertised information appeared to be limited in scope, non-sensitive and several years old.
The databases advertised by TheHatman reportedly range from thousands to more than a million records. The alleged McDonald’s database contains more than 1.7 million records, while the advertisements claim more than 800,000 records from Tata Consultancy Services, over 425,000 from Vodafone, more than 250,000 from HCL Technologies, around 185,000 from InterContinental Hotels, more than 170,000 from Kyndryl and smaller datasets from other organizations.
The advertised information generally includes names, email addresses, job titles, phone numbers and addresses. Some of the alleged datasets also contain employee IDs, service accounts and other Microsoft Azure or Entra tenant account information.
TheHatman has reportedly provided sample records from each advertised database so potential buyers can verify the information before purchasing it.
Cybersecurity intelligence company Hudson Rock analyzed the leaked datasets and said they contain what it described as foundational corporate directory information. The company also identified structured data containing active domains and tenant-specific Microsoft .onmicrosoft.com structures.
Hudson Rock said the datasets include service accounts and names of global administrators, information that could potentially be used to support social engineering and spearphishing attacks. The cybersecurity company expressed high confidence that the data itself is authentic, although it said the exact method used to gain access and extract the information remains unknown.
The authenticity of the alleged breaches has not been independently confirmed. BleepingComputer said it was unable to independently verify the data and had contacted the listed companies for comment, but had not received responses from the organizations by the time of publication.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Article Source: BleepingComputer





