VYPR
breachPublished Aug 16, 2026· 1 source

Massive Azure Credential Theft Campaign Exposes Millions of Records from McDonald's, Vodafone, and More

A threat actor known as 'TheHatman' is selling vast amounts of stolen employee data from major corporations, including McDonald's and Vodafone, exfiltrated from Azure and Entra tenants using compromised credentials.

A significant data exfiltration campaign is underway on dark web forums, where a threat actor identified as "TheHatman" is systematically selling large volumes of internal employee data stolen from major global corporations. The actor claims to have accessed these records directly from victim organizations' Azure and Entra tenants by leveraging compromised credentials. The scale of the operation is substantial, with "TheHatman" listing data from at least nine Fortune 500 companies across various sectors including IT services, hospitality, telecommunications, and retail.

Among the most prominent victims are McDonald's Corporation, with over 1.7 million exposed records, followed by Tata Consultancy Services with approximately 800,000, and Vodafone with around 425,000 records. Other affected companies include HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels, with data dumps ranging from tens of thousands to hundreds of thousands of records.

Researchers from Hudson Rock, who have analyzed sample datasets, confirm the high credibility of the information. The leaked data consistently includes corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, and manager assignments. Crucially, the datasets also contain access and group mapping information, including details on service accounts and, in some instances, Global Administrator accounts, providing attackers with a clear roadmap for further exploitation.

While "TheHatman" asserts that compromised credentials were the sole method of access, the exact initial entry point remains unconfirmed. Potential vectors include infostealer malware harvesting session tokens from employee devices, successful phishing campaigns yielding administrative access, inadequate multi-factor authentication (MFA) enforcement within affected tenants, or the abuse of third-party APIs with overly broad permissions. The consistent format and rapid dissemination of the data suggest a highly systematized, likely automated, process once initial access was gained.

Hudson Rock researchers have also identified compromised Azure credentials linked to infostealer infections on devices belonging to employees at several of the affected companies, including TCS, Gap Inc., HCL Technologies, and Kyndryl. In one documented case, a single compromised device contained numerous corporate credentials and session cookies, granting direct access to a Kyndryl Azure Active Directory account.

The nature of the victims—large multinational corporations rather than a broad range of smaller businesses—strongly suggests that this campaign targets stolen credentials specifically, rather than exploiting a systemic vulnerability within the Azure platform itself. This indicates a focus on high-value enterprise access.

The real-world implications of this breach extend far beyond the initial data exposure. Threat actors frequently weaponize such structured directory information to conduct highly convincing business email compromise (BEC) and spear-phishing attacks. The detailed reporting lines and job titles enable impersonation of management or IT staff, facilitating fraudulent financial transfers or the coercion of employees into divulging MFA codes.

Furthermore, the exposure of service account and administrator names provides initial access brokers and ransomware groups with valuable intelligence for identifying and targeting critical infrastructure. Organizations are urged to prioritize credential hygiene, implement continuous monitoring for infostealer-compromised credentials, enforce robust MFA across all tenant portals, and rigorously scrutinize third-party API permissions to mitigate the risk of similar attacks.

Synthesized by Vypr AI