Hacker Claims Millions of Records Stolen From Azure Tenants

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A threat actor calling themselves 'TheHatman' claims to have stolen millions of employee records from Microsoft Azure environments belonging to companies including McDonald's, Vodafone, Kyndryl, TCS, HCL Technologies, IHG, Gap, Hexaware, and Wyndham Hotels, and is offering the data for sale on cybercrime forums. Samples reportedly include employee IDs, job titles, departments, group memberships, service accounts, and details of Global Administrator accounts, consistent with Azure directory exports. Security researchers link the exposure to previously circulated credentials from infostealer infections, with possible entry via stolen session tokens, phishing, weak MFA, or over-permissioned third-party integrations. TCS disputes any breach of its systems, saying the referenced data is over four years old and limited to basic details. Experts warn the leaked data forms a 'precision targeting kit' for spear-phishing and helpdesk impersonation attacks, and call for stronger conditional access policies and separation of identity from data access controls.

4m read timeFrom itsecurityguru.org
Post cover image

Questions this post answers

How did attackers reportedly gain access to steal employee data from Azure tenants?

Attackers likely used credentials previously compromised through infostealer malware infections, which had circulated on criminal marketplaces before being used to access cloud environments. Other possible entry points include stolen session tokens, phishing, weak multi-factor authentication protections, and third-party integrations granted excessive permissions into the affected Azure environments. Teams hardening cloud identity controls can track evolving Azure attack patterns on daily.dev.

What kind of employee data was allegedly stolen in the Azure directory breach affecting McDonald's, Vodafone, and TCS?

The leaked data reportedly includes employee IDs, job titles, departments, reporting structures, group memberships, service account labels, and details of Global Administrator accounts. Security experts describe this combination as a precision targeting kit useful for spear-phishing, phone-based social engineering, and helpdesk impersonation attacks against higher-value accounts. Security teams assessing exposure from directory leaks can follow incident details like this on daily.dev.

Why can stolen employee directory data still be dangerous even if it is several years old?

Organizational charts change slowly and service account naming conventions rarely change, so historic breached data dumps can remain useful for planning and executing new attacks years after the original compromise. This is why old employee data, like the information TCS said was over four years old, still carries phishing and impersonation risk. Anyone evaluating stale breach data risk can keep up with expert analysis on daily.dev.

8 Impressions