Security & Risk5 min

"TheHatman" Claims Exfiltration of 3.1 Million Azure Records from McDonald's, TCS, and Vodafone via Compromised Credentials

Analista de segurança monitorando alerta de exfiltração de dados em painel Azure Active Directory em sala de operações de segurança corporativa

A threat actor identified as "TheHatman" claims to have extracted corporate directories from Azure and Entra ID tenants of companies such as McDonald's (1.7 million records), TCS, and Vodafone. None of the organizations have publicly confirmed the breach.

A threat actor identified by the alias "TheHatman" published claims in cybercrime forums last week, alleging possession of vast corporate directories extracted from Microsoft Azure and Entra ID tenants via compromised credentials. The campaign, reported by The Register and several specialized publications on August 17, claims to target multinationals across various sectors, with more than 3.1 million employee records claimed in total.


The actor claims to possess over 1.7 million records from McDonald's, approximately 800,000 from Tata Consultancy Services (TCS), 425,000 from Vodafone, 250,000 from HCL Technologies, and 170,000 from Kyndryl, along with smaller volumes from Gap Inc., InterContinental Hotels Group (IHG), Wyndham Hotels, and Hexaware. The alleged data includes names, corporate email addresses, phone numbers, employee IDs, job titles, management hierarchies, service accounts, and listings of global Azure Active Directory administrators.


McDonald's, Vodafone, TCS, HCL, Kyndryl, and the other cited organizations had not publicly commented by the time of publication.


The Attack Vector: Insecure Configurations, Not Product Flaw


"TheHatman" did not describe the exact method of intrusion beyond citing compromised credentials. Researchers at Hudson Rock, who analyzed samples of the data put up for sale, described the access vector as "inconclusive" based on the available evidence. Industry hypotheses include infostealers harvesting session tokens from compromised corporate machines, targeted phishing against accounts with administrative privileges, absent or misconfigured multi-factor authentication in specific tenants, and third-party integrations with excessive cross-tenant read permissions.


Microsoft has not confirmed any new vulnerabilities in Azure or Entra ID related to the campaign. "TheHatman" claims to have exploited insecure configurations, not a product flaw, which has direct implications for responsibility: if the vector is confirmed as misconfiguration, the duty to rectify it falls on the tenant operators, not on the platform.


Why Global Administrator Listings Amplify Risk


Conventional dumps of corporate directories have limited value in the underground market due to the available volume. This campaign is different: "TheHatman" claims that the datasets include service accounts and global administrators from Azure Active Directory. These fields turn an HR directory into an operational attack map. A compromised global administrator has the authority to create new credentials, grant access to applications, disable MFA for specific accounts, and modify conditional access policies throughout the tenant, without further approval in standard configurations.


For a CISO, the presence of these fields in the alleged data is a signal for the most urgent action, regardless of official confirmation of the breach.


Reading by Geography: Chicago, Chennai, and London


The list of alleged victims covers three distinct risk geographies. McDonald's operates global workforce management systems from Chicago, with personnel data distributed across Europe, Asia-Pacific, and Latin America. TCS and HCL Technologies, headquartered in Mumbai and Noida respectively, together employ over 600,000 professionals in operations across more than 50 countries, with clients concentrated in financial services and telecommunications in the U.S. and Europe. Vodafone, a British operator with commercial presence in 20 markets, holds Azure directories subject to the GDPR in Europe and equivalent regulations in the Middle East and South Africa.


The combination of sectors suggests that the actor did not select victims by vertical but by shared configuration vulnerability in Azure Entra ID, possibly via a common identity integration partner or SSO provider across multiple global tenants.


What to Prioritize Now


The immediate response does not depend on confirmation. CISOs of organizations operating Azure tenants with a global scope should review global administrator permissions, audit privileged access logs from the past four weeks, and enable alerts for Privileged Identity Management (PIM) for unauthorized privilege escalation. The window between silent exfiltration and underground forum publication is often weeks; in this case, the public alert came first.


Campaigns like the one attributed to "TheHatman" demonstrate why the identity perimeter has surpassed the network perimeter as the primary attack surface in modern corporate environments: there is no firewall that blocks a valid credential being used by the wrong operator.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk