Hacker claims 3.6 million records stolen from major companies’ Azure environments – Expert Comments

A threat actor known as TheHatman is selling databases allegedly stolen from the Microsoft Azure environments of major companies after gaining access with compromised credentials. Cybercrime intelligence company Hudson Rock investigated the leaks and said they contain "foundational corporate directory attributes," "active domains, and tenant-specific .onmicrosoft.com structures" and are "highly likely authentic."

The attacker claims to have obtained 3.64 million records from organizations including McDonald’s, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels, Gap, Wyndham Hotels, Hexaware and Kyndryl.

The largest alleged dataset contains more than 1.7 million McDonald’s employee records, followed by more than 800,000 from Tata Consultancy Services and 425,000 from Vodafone. The data reportedly includes names, employee IDs, email addresses, job titles, phone numbers, addresses, service accounts and other Azure tenant information.

Seemant Sehgal, Founder & CEO, BreachLock:

“This is a reminder that the perimeter most organizations are defending is not where the adversary is operating. A valid credential, once stolen, moves through an environment the same way a legitimate user does. The attacker does not need to break anything. What makes this particularly significant is the nature of the data itself. Directory attributes, tenant structures, and employee identifiers are the raw materials for follow-on attacks, targeted phishing, or supply chain access.

Security teams need to ask whether a credential that was exposed six months ago is still giving someone access to a cloud environment today. Perimeter controls can be strong and still leave that kind of access untouched. The organizations downstream from the initial compromise are often the ones who feel it most. The real test is understanding what an attacker could do with a compromised credential, where it could take them, and whether anyone would know it was being used."

John Carberry, Solution Sleuth, Xcape, Inc.:

“Exfiltrating internal directory structures and employee credentials across corporate cloud tenants creates an immediate risk of targeted spear phishing, business email compromise, and privilege escalation. The mass exposure of 3.64 million records from Fortune 500 Microsoft Azure environments highlights a widespread failure in identity boundary enforcement rather than a cloud platform vulnerability. Organizations must continuously audit user account activity, paying special attention to accounts with elevated privileges, to detect anomalous directory enumeration or session hijacking.

Given that Azure tenant attributes, active domains, and service account details were exfiltrated, affected companies should immediately rotate credential stores, reset application registration secrets, audit service principal permissions, and review federated domain trust relationships. Security leaders must mandate phishing-resistant multi-factor authentication, restrict tenant export rights, and monitor endpoint infostealer logs to stop credential theft before attackers map internal cloud architecture.

Critical Takeaways:

• Identity perimeter failure: The exposure stems from compromised credentials and infostealer malware, not a zero-day flaw in Microsoft Azure infrastructure.
• Tenant remediation: Affected organizations must reset application secrets, audit service principal privileges, and review federated trust relationships immediately.
• Privileged account auditing: Security teams must enforce strict conditional access and audit user accounts with elevated privileges to intercept active session abuse.

Blaming the cloud provider for stolen credentials is like blaming the lock manufacturer when you leave your house key under the doormat.”

Articles similaires

Opinion

31 August 2026

Global watchdog names AI-driven cyberattacks the most immediate threat to financial stability - Expert Comments

The Financial Stability Board (FSB) has identified the impact of frontier AI on cyberattacks as (…)

Opinion

28 August 2026

100+ companies call for collective AI cyber defense actions - AI threat experts weigh in

More than 100 companies came together to make an open plea for collective action (…)

Opinion

26 August 2026

FBI investigates newly disclosed breach of U.S. water technology supplier – Expert Comments

The FBI is investigating a previously unreported cyberattack on Micro-Comm, a Kansas company (…)