A cybercriminal claims to be offering 3.64 million employee records from major companies for sale. The data is said to have been obtained from Microsoft Azure and Entra environments accessed using stolen login credentials. Companies mentioned include McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS). However, some companies deny that their systems have been hacked.
The attacker, who operates under the name TheHatman, has been posting datasets on cybercrime forums since July 31. The largest collection is said to come from McDonald’s and contain more than 1.7 million records. Over 800,000 records from TCS are being offered, followed by Vodafone with 425,000 and HCL Technologies with 250,000 records.
The list also includes InterContinental Hotels Group (185,000), Kyndryl (170,000), Gap (80,000), Hexaware Technologies (20,000), and Wyndham Hotels (9,000). TheHatman is providing samples with the offered databases so potential buyers can assess the content, BleepingComputer reports.
Internal structure visible
According to the attacker, the datasets include names, work email addresses, employee ID numbers, job titles, phone numbers, and addresses. In some cases, the attacker also reportedly stole service accounts and other data from the Azure tenant.
Cybersecurity firm Hudson Rock analyzed samples of the data being offered. According to the researchers, the data structure matches information found in corporate directories, including active domains and the .onmicrosoft.com addresses characteristic of Microsoft tenants. The files also reportedly contain the names of Global Administrators.
Such information can be used for follow-up attacks. With knowledge of job titles, departments, and administrator accounts, attackers can, for example, launch targeted phishing campaigns or impersonate managers and IT staff.
However, the authenticity of the full datasets has not been confirmed. Hudson Rock is highly confident that the data is genuine, but BleepingComputer was unable to independently verify this.
TCS and Gap deny breach
Furthermore, two of the companies mentioned dispute that a recent hack took place. TCS investigated the claim and says it found no credible evidence of a breach in its own systems or customer environments. According to the company, the data provided appears to be at least four years old and reportedly contains only basic employee information.
It is noteworthy that TheHatman claims to have used password spraying and MFA fatigue against TCS. In password spraying, attackers try a limited number of commonly used passwords on large numbers of accounts. In MFA fatigue, attackers target a user with authentication requests in the hope that they will eventually approve one. TCS says it has been using measures against such techniques for more than two years.
Gap also states that it has found no evidence that its business systems were compromised. According to the company, the information offered is limited, non-sensitive, and several years old.
Attack vector remains unclear
This does not confirm that all the data being offered was actually extracted from Azure during recent attacks. TheHatman claims that compromised credentials were used, but independent evidence for that claim is lacking.
Hudson Rock did find Azure login credentials at most of the affected organizations that had previously been stolen by infostealers. The researchers therefore consider it possible that stolen credentials played a role. However, this does not prove that these specific accounts were used to collect the datasets in question.
Other possibilities include phishing, stolen session tokens, or the misuse of integrations with broad access privileges. For now, there are no indications that a vulnerability in Azure or Entra itself is behind the alleged data theft.