Skip to main content
Emerging ThreatsData Breaches

Azure Breach Exposes Millions of Employee Records at Top Firms

Blurred employees walk past server racks in a brightly-lit corporate office or data center interior.

“McDonald's accounts for the largest alleged dataset on TheHatman's shopping list, with 1.7 million records purportedly up for grabs.”

TheHatman's advertised haul and the named victims

A threat actor using the name "TheHatman" is advertising millions of employee records said to have been siphoned from Microsoft Azure environments belonging to nine organizations, according to research published by Hudson Rock. Hudson Rock's list includes McDonald's (1.7 million records), Tata Consultancy Services (800,000), Vodafone (425,000), and HCL Technologies (250,000), with IHG Hotels & Resorts, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts also named.

Hudson Rock's assessment of authenticity

Hudson Rock assessed the data as "highly likely authentic," citing corporate email addresses and structures it said are consistent with exports from Microsoft Azure directory services. The security shop reviewed samples and reported evidence such as organizational structures and directory-style exports that supported its judgment.

What the records reportedly contain — and why that matters

Samples reviewed by Hudson Rock reportedly include more than names and work email addresses. The alleged dataset is said to contain phone numbers, physical addresses, employee IDs, job titles, departments, office locations, reporting structures, group memberships, and service account details. Some records purportedly identify accounts with Global Administrator privileges — information that the report notes could give attackers a clear map of high-value targets for follow‑on attacks. Even if passwords are not present, knowledge of who "holds the keys to the kingdom" can make a highly effective phishing shortlist.

How the attacker may have gained access — competing theories

TheHatman claims to have used compromised credentials, but Hudson Rock could not independently establish the initial access vector. The research firm floated several possibilities: credentials or session cookies stolen by infostealer malware, phishing, weak or absent multifactor authentication, and overly permissive third‑party applications. Hudson Rock added that its infostealer database contained compromised Microsoft cloud credentials associated with most of the named companies, although it could not link those credentials to TheHatman's alleged access.

Response from Tata Consultancy Services and outreach to other parties

The Register contacted all organizations named by Hudson Rock and asked Microsoft whether it was aware of a wider campaign targeting Azure or Entra customers. Tata Consultancy Services supplied the statement it made to India's stock exchange, saying: "The Company has received threat‑intelligence alerts alleging possible exposure of certain employee information." Tata said it had investigated and "has not found any credible evidence of a breach of TCS systems or customer environments."

Tata added that "The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted." The company also addressed the attacker's claimed methods: "The attacker claims to have used password spray and Multi‑Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely." Tata closed with: “The Company will continue to assess any new information that becomes available and take appropriate action, if required. The Company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us.”

What this means for technologists, procurement leaders, and adversaries

  • Technologists and security teams: prioritize detection of infostealer activity, review MFA coverage and defenses against MFA fatigue and password‑spray techniques, and audit service‑account and Global Administrator assignments in Azure directory services.
  • Procurement and application owners: examine permissions granted to third‑party applications tied to corporate Azure tenants and consider tightening scopes and consent policies where exports of directory data are possible.
  • Adversaries and opportunists: the alleged dataset — if authentic — offers a ready list of people with elevated privileges and the metadata needed to craft targeted phishing and account‑takeover campaigns.

The core question remains straightforward and unresolved in Hudson Rock's report and in responses so far: how, exactly, did TheHatman allegedly walk out of nine corporate directories? Hudson Rock and Tata have set out competing details — assessment of authenticity versus an assertion of no credible breach — and The Register has reached out to the other named organizations and to Microsoft for further comment. Until more forensic linkage is published, defenders must treat the advertised claims seriously while investigators attempt to connect the dots between stolen credentials, infostealer repositories, and directory exports.

Source: The Register — Crook hawks millions of records allegedly plundered from corporate Azure tenants