Key Takeaways
- The threat actor “TheHatman” is selling employee directory data stolen from Azure/Entra tenants of multiple Fortune 500 companies, with McDonald’s leading at >1.7 M records.
- Leaked data includes names, corporate emails, phone numbers, physical addresses, employee IDs, job titles, departments, manager/reporting structures, and privileged account information such as service‑account and Global Administrator details.
- The exposure enables highly convincing spear‑phishing, business‑email‑compromise (BEC), and privilege‑escalation attacks, giving adversaries a ready‑made targeting map.
- Likely infection vectors involve infostealer malware harvesting session tokens or credentials, phishing that yields admin access, weak MFA enforcement, or abuse of third‑party API integrations with excessive permissions.
- Hudson Rock researchers have corroborated the credibility of the dumps and identified compromised Azure credentials tied to infostealer infections at several victim firms.
- Organizations must prioritize credential hygiene—continuous monitoring for stolen credentials, enforcement of MFA across all portals, and tight control of third‑party API permissions—to mitigate the risk posed by this campaign.
Overview of the Azure Data Exfiltration Campaign
A large‑scale data‑theft operation is unfolding on underground forums, where the seller known as “TheHatman” is offering internal employee directories harvested from Azure and Entra tenants of some of the world’s biggest corporations. The campaign has rapidly expanded, with listings for at least nine Fortune 500‑level enterprises appearing over the past week. The data sets are being sold individually, and the sheer volume of records on offer underscores the severity of the breach.
Scale and Scope of the Leaked Records
McDonald’s Corporation tops the list with more than 1.7 million exposed employee records, followed by Tata Consultancy Services (TCS) at roughly 800 k, Vodafone at about 425 k, and HCL Technologies at around 250 k. Additional victims include InterContinental Hotels Group (~185 k), Kyndryl (~170 k), Gap Inc. (~80 k), Hexaware Technologies (~20 k), and Wyndham Hotels (~9 k). Together, these figures represent a trove of personal and organizational data that spans multiple industries, including IT services, hospitality, telecommunications, retail, and logistics.
Structure and Content of the Dumped Data
Hudson Rock researchers who examined sample dumps confirm that the information is highly credible. The leaked files follow a consistent template mirroring standard Azure directory exports. Core fields contain full names, corporate email addresses (both from active company domains and the tenant‑specific onmicrosoft.com format), phone numbers, and physical addresses. Beyond basic contact details, the dumps expose employee IDs, job titles, department affiliations, manager assignments, and direct‑report relationships. Notably, the data also includes access and group‑mapping details, such as service‑account listings and, in some instances, Global Administrator accounts.
Implications of Exposing Privileged Account Information
The inclusion of service‑account and administrator data is particularly alarming. With this intelligence, attackers gain a precise map of high‑privilege identities within the target environment, facilitating spear‑phishing campaigns that impersonate IT staff or senior leaders, business‑email‑compromise schemes that trick employees into approving fraudulent transfers, and targeted privilege‑escalation attempts. For initial‑access brokers and ransomware groups, the leaked directory acts as a targeting shortcut, reducing the reconnaissance phase and accelerating the path to critical assets.
Uncertainty Surrounding the Initial Intrusion Vector
While TheHatman repeatedly claims the data was obtained “using compromised credentials,” the exact method of entry remains unconfirmed. Hypotheses proposed by security analysts include infostealer malware harvesting session tokens from employee workstations, phishing campaigns that yielded administrative‑level access, tenants lacking enforced multi‑factor authentication (MFA), or abuse of third‑party API integrations that were granted overly broad read permissions. The uniformity and speed of the successive dumps suggest a systematic, likely automated, exfiltration process once an initial foothold was secured.
Evidence Supporting the Infostealer Theory
Hudson Rock’s investigation uncovered compromised Azure credentials linked to infostealer infections on machines associated with several affected organizations, including employees at TCS, Gap Inc., HCL Technologies, and Kyndryl. One compromised device was found to store dozens of corporate credentials and hundreds of sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account. The fact that only large multinational enterprises appear in the campaign—rather than a broad cross‑section of smaller businesses—points to targeted exploitation of stolen credentials rather than a widespread Azure platform vulnerability.
Real‑World Risks Enabled by the Leaked Directory Data
Structured directory information is a powerful weapon in the hands of threat actors. Accurate reporting lines, job titles, and departmental data allow attackers to craft highly convincing spear‑phishing emails that mimic internal communications, increasing the likelihood of success. Exposure of service‑account and administrator names provides a targeting map for initial‑access brokers and ransomware affiliates seeking the quickest route to privileged systems. Consequently, the leaked data amplifies the risk of business‑email‑compromise, credential theft, lateral movement, and data‑exfiltration campaigns against the victim organizations.
Recommended Defensive Measures for Affected and Potentially Targeted Organizations
In light of this campaign, organizations should treat credential hygiene as a core component of their security posture. Essential steps include:
- Deploying continuous monitoring solutions that detect the use of stolen or infostealer‑compromised credentials in real time.
- Enforcing MFA universally across all Azure and Entra portals, with particular emphasis on privileged accounts and service‑account logins.
- Conducting regular reviews of third‑party API permissions and integrations, ensuring they follow the principle of least privilege.
- Implementing anomaly‑based user‑behavior analytics to spot unusual access patterns, such as logins from unfamiliar locations or at odd hours.
- Educating employees about phishing and social‑engineering tactics, emphasizing verification of requests for sensitive actions even when they appear to originate from trusted internal sources.
By tightening credential controls and improving visibility into authentication events, companies can reduce the likelihood that attackers will leverage stolen directory data to gain a foothold, thereby mitigating the downstream impact of campaigns like the one orchestrated by “TheHatman.”

