Fortune 500 Companies Targeted in Azure Data Theft Campaign
A threat actor, operating under the moniker 'TheHatman,' is reportedly selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations. The campaign has impacted major global enterprises across various sectors, including IT services, hospitality, telecommunications, retail, and logistics. Companies such as McDonald's Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels are among those affected. The threat actor claims the data was exfiltrated from Azure/Entra instances using leaked credentials. Cybersecurity firm Hudson Rock confirmed the legitimacy of the internal employee directories being sold, noting that the identified email addresses and field names match Azure directory exports. The largest data dump, from McDonald's, contains over 1.7 million records, while TCS has 800,000, Vodafone 425,000, HCL Technologies 250,000, and IHG 185,000.