A large-scale Azure exfiltration campaign has exposed millions of employee records from major enterprises after a threat actor known as “TheHatman” allegedly used compromised credentials to access Azure/Entra tenants. The leaked directory data from companies including McDonald’s, Vodafone, TCS, HCL Technologies, IHG, and Kyndryl could enable spear-phishing, business email compromise, and privilege escalation attacks. #TheHatman #Azure #Entra #McDonalds #Vodafone #TCS #HCLTechnologies #IHG #Kyndryl
Keypoints
- TheHatman is advertising massive employee directory dumps on cybercrime forums.
- The stolen records appear to come directly from Azure/Entra tenant portals.
- McDonald’s, TCS, Vodafone, HCL Technologies, IHG, Kyndryl, and others are affected.
- The leaked data includes names, emails, phone numbers, job titles, managers, and access groups.
- Compromised credentials, likely from infostealer infections, are suspected in the initial access.