← Back to feed
Threat Actors & CampaignsEmerging2 sourcesAug 18, 2026 · 09:06via Help Net Security

Hacker claims millions of records stolen from corporate Azure tenants

Brief

A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks.

The threat actor, known as “TheHatman,” has reportedly posted internal employee directories belonging to companies including McDonald’s, Vodafone, Kyndryl, Tata Consultancy Services (TCS), HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies, and Wyndham Hotels for sale on cybercrime forums.

According to various sources, samples of the data contained corporate email addresses and fields consistent with standard Azure directory exports. However, the exact method used to gain access remains unconfirmed.

Read more on Help Net Security

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Help Net SecurityPrimary··trust 1.14

Hacker claims millions of records stolen from corporate Azure tenants

A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock.

Over the past week, the threat actor has posted a string of large internal employee directories on cybercrime forums, claiming that each was pulled directly from the victim organization’s Azure tenant. In addition to McDonald’s, Vodafone, Kyndryl, and TCS, … More →

The post Hacker claims millions of records stolen from corporate Azure tenants appeared first on Help Net Security .

Read more →
IT Security Guru··trust 0.95

Hacker Claims Millions of Records Stolen From Azure Tenants

A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks.

The threat actor, known as “TheHatman,” has reportedly posted internal employee directories belonging to companies including McDonald’s, Vodafone, Kyndryl, Tata Consultancy Services (TCS), HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies, and Wyndham Hotels for sale on cybercrime forums.

According to various sources, samples of the data contained corporate email addresses and fields consistent with standard Azure directory exports. However, the exact method used to gain access remains unconfirmed.

Researchers said compromised credentials linked to many of the affected organisations had previously circulated following infostealer infections. Possible routes into the environments include stolen session tokens, phishing, weak MFA protections, or third-party integrations with excessive permissions.

Employee data creates a roadmap for attackers

The allegedly stolen information includes employee IDs, job titles, departments, reporting structures, group memberships, service accounts, and, in some cases, details of Global Administrator accounts.

Cian Heasley, Principal Consultant at Acumen Cyber , warned that information that initially appears relatively harmless can provide the foundations for further attacks.

“Names, job titles, phone numbers, service account labels, and global administrator identities are precisely the precursors required to build convincing spear-phishing, phone based social engineering and helpdesk request employee impersonation attacks against higher value accounts or systems,” Heasley said.

He also warned against dismissing older employee information as irrelevant.

Read more →