StratosAlly – Cybersecurity for digital safety

Azure Credential Theft Campaign Exposes Millions of Enterprise Records

Picture of StratosAlly

StratosAlly

Azure Credential Theft Campaign Exposes Millions of Enterprise Records

A major cybercrime campaign is showing just how dangerous stolen cloud credentials can be. A threat actor known as “TheHatman” is reportedly selling employee-directory data allegedly extracted from Microsoft Azure and Entra environments of several major global companies. Researchers say the campaign has exposed more than 3.6 million records across at least nine organizations.

The reported victims include McDonald’s, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, Kyndryl, InterContinental Hotels Group, Gap Inc., Hexaware Technologies and Wyndham Hotels. McDonald’s reportedly has the largest dataset, with more than 1.7 million records, followed by TCS with around 800,000, Vodafone with approximately 425,000, and HCL Technologies with about 250,000.

But the concern isn’t simply the number of records.

The leaked datasets reportedly contain employee names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, managers and reporting relationships. In some cases, the information also includes service-account details and Global Administrator account listings.

That information could become a powerful weapon for attackers. Knowing exactly who reports to whom gives threat actors the ingredients for highly convincing spear-phishing, business email compromise and social-engineering attacks. A fake message from an “IT administrator” or senior manager becomes much more believable when the attacker already knows the organization’s internal structure.

The exact initial entry point remains unclear. The threat actor claims to have used compromised credentials, while Hudson Rock researchers point to possibilities including infostealer malware, stolen session cookies, phishing, weak MFA enforcement and overly permissive third-party integrations. Researchers also identified compromised Azure credentials associated with infostealer infections linked to several affected organizations.

One compromised device reportedly contained dozens of corporate credentials and hundreds of sensitive session cookies, including access connected to a Kyndryl Azure Active Directory account.

Importantly, the evidence currently points toward credential compromise rather than an underlying Azure platform vulnerability. The incident highlights a bigger reality of modern cloud security: attackers don’t always need to break through the front door when they can obtain a legitimate identity.

Let’s refine your stalking skills; go through our Instagram and LinkedIn.

more Related articles