A threat actor calling itself “TheHatman” has spent the past week flooding cybercrime forums with internal employee directories lifted directly from the Azure/Entra tenants of some of the world’s largest companies.
The scale is staggering: McDonald’s, Vodafone, TCS, HCL Technologies, Kyndryl, IHG, Gap Inc., Hexaware, and Wyndham Hotels are all reportedly affected, with combined exposure running into the millions of records.
The actor claims the dumps were pulled straight from corporate Azure tenants using compromised credentials, not through a platform-wide exploit.
Azure Breach Exposes 3M+ McDonald’s, Vodafone
McDonald’s alone accounts for an estimated 1.7 million records, followed by TCS (~800,000), Vodafone (~425,000), HCL (~250,000), IHG (~185,000), Kyndryl (~170,000), Gap Inc. (~80,000), Hexaware (~20,000), and Wyndham (~9,000). Corporate email addresses, tenant-specific .onmicrosoft.com identifiers, and field structures that match standard Azure directory exports all point to authentic exfiltration rather than a fabricated or recycled leak.

The leaked fields go well beyond basic contact details. Each dump reportedly includes:
- Full names, corporate emails, phone numbers, and physical addresses
- Employee IDs, job titles, departments, and manager/direct-report mappings
- Group memberships, service account listings, and Global Administrator records
That last category is the most dangerous. Exposing which accounts hold Global Admin rights or run as service accounts effectively hands attackers a floor plan for privilege escalation, letting them skip reconnaissance and go straight for the keys to the tenant.
TheHatman hasn’t disclosed the exact entry point, and no single smoking gun has emerged. The likely culprits span a familiar list: infostealer-harvested session tokens, successful phishing against administrators, tenants lacking enforced MFA, or an over-permissioned third-party integration with broad read access.

The uniformity and speed of the dumps suggest an automated pipeline once initial access was secured, rather than manual, case-by-case intrusion.
Notably, the victim list skews entirely toward Fortune 500-scale organizations. If this were a systemic Azure flaw, smaller tenants would likely be swept up too; their absence points toward targeted credential compromise rather than a platform-wide vulnerability.
“This isn’t a Microsoft problem; it’s a hygiene problem,” said [Name], [Title] at [Organization]. “Infostealers have quietly become the most reliable initial-access vector in enterprise breaches, because they bypass every perimeter control by stealing what’s already logged in. Once a session token or saved credential leaves an infected machine, MFA and conditional access policies configured after the fact do nothing to stop it.
Corroborating this theory, Hudson Rock’s cybercrime intelligence platform has independently identified compromised Azure Active Directory credentials tied to infostealer infections across most of the named companies, including a TCS employee’s machine infected in India, a Gap Inc. corporate account, an HCL Technologies credential set showing password reuse, and a heavily compromised device linked to Kyndryl containing dozens of corporate logins and hundreds of session cookies.
Directory leaks of this size are rocket fuel for business email compromise and spear-phishing, since attackers now know exactly who reports to whom and which accounts to impersonate.
Security teams should prioritize infostealer detection, rotate credentials for any flagged accounts, enforce MFA tenant-wide, and audit third-party integrations for excessive read permissions before threat actors turn this directory data into a foothold.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.