Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor known as “TheHatman” is advertising millions of employee records allegedly stolen from Azure/Entra tenants of Fortune 500 firms including McDonald’s (1.7M+ records), TCS (800k), Vodafone (425k), HCL, IHG, Kyndryl, Gap, Hexaware, and Wyndham. Data appears to consist of legitimate Azure directory exports containing names, emails, phone numbers, job titles, manager details, group memberships, service accounts, and privileged accounts. Hudson Rock assesses the data as highly likely authentic and attributes the campaign to compromised credentials from a targeted infostealer operation rather than an Azure zero-day. Exposed privileged and service accounts raise risks of follow-on spear-phishing and privilege-escalation attacks.
https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/

