Hacker Claims 3.6 Million Azure Accounts Stolen From Major Companies
A cybercriminal using the alias “TheHatman” has put up for sale 3.6 million employee records allegedly stolen from the Microsoft Azure infrastructure of giants like McDonald's, Vodafone, and Tata. The companies, however, deny the claims, stating the data is old.
What Happened
The cybersecurity world is abuzz with claims made by a threat actor using the alias “TheHatman.” The hacker claims to have stolen and put up for sale more than 3.6 million employee records from the Microsoft Azure cloud infrastructure of numerous Fortune 500 companies, including McDonald's, Vodafone, Gap Inc., and Tata Consultancy Services (TCS). A series of posts on cybercrime forums since July 31st has created a significant wave of concern in the corporate world. At the heart of these allegations is the claim that one of the companies' most valuable assets, their employee data, was exfiltrated directly from Azure systems using compromised administrator credentials. This incident once again highlights the critical importance of cloud infrastructure security and how even a single weak link can lead to massive consequences. The largest database offered for sale is alleged to belong to McDonald's employees, with 1.7 million records. A breach claim of this magnitude concerns not only the named companies but all organizations that have migrated their business processes to cloud systems. While it remains unclear how and for what purpose the attacker will use this data, the affected companies have denied the allegations and announced they have launched their own internal investigations.
What Data Was Leaked
The contents of the data offered for sale by “TheHatman” paint a nightmarish scenario for any corporation. According to the claims, the massive dataset of 3.64 million records contains highly sensitive and detailed information about employees. This information includes critical data such as full names, employee IDs, corporate email addresses, job titles and position information, mobile phone numbers, postal addresses, and service accounts. The 1.7 million-record dataset allegedly belonging to McDonald's alone poses a significant risk. The second-largest data package belongs to the technology giant Tata Consultancy Services (TCS), with over 800,000 records. Similarly, databases with hundreds of thousands of records are listed for other companies. This type of data is a goldmine for cybercriminals. The information can be used to launch highly sophisticated phishing attacks targeting employees, create fake identities, conduct corporate espionage, or serve as a stepping stone for larger cyberattacks. In particular, the combination of job titles and contact information can facilitate CEO fraud attacks, where attackers impersonate or target senior executives.
How Did the Attack Happen
Although there is no clear and verified information about the technical details of the attack yet, statements from the threat actor and one of the affected companies provide some clues. In the forum posts, the hacker states they “downloaded the data directly from the Azure Tenant using compromised credentials.” This statement indicates that the attacker somehow obtained the login information of an authorized user to infiltrate the system. A statement from Tata Consultancy Services (TCS) mentioned that the attacker claimed to have used “password spray” and “Multi-Factor Authentication (MFA) fatigue” as the attack vectors. These methods are quite common among cybercriminals.
Password Spraying: In this technique, instead of trying hundreds of different passwords for a single user account, attackers try one common and weak password (e.g., “Summer2026!”) against hundreds of different user accounts. This method aims to bypass account lockout mechanisms that are triggered by multiple failed login attempts on a single account.
MFA Fatigue: This is more of a social engineering attack. When the attacker tries to log in with the stolen username and password, an MFA approval notification is sent to the user's phone. The attacker repeats this process multiple times, flooding the user with notifications. After a while, the user, either annoyed by the notifications or mistakenly thinking one is a legitimate request, approves it, inadvertently allowing the attacker to gain access. Although the companies deny these claims, the attacker's alleged use of these methods underscores the importance of the human factor and proper MFA configuration in corporate security.
Who Was Affected
The companies whose data was allegedly leaked by “TheHatman” are giants in their respective industries. The organizations on the list include:
- McDonald's (over 1.7 million records)
- Tata Consultancy Services (TCS) (over 800,000 records)
- Vodafone (over 425,000 records)
- HCL Technologies (over 250,000 records)
- Gap Inc. (over 80,000 records)
- InterContinental Hotels (IHG)
- Kyndryl
What You Can Do
In the face of such large-scale and corporate-focused leak claims, there are measures that both individuals and organizations can take. If you are or were an employee of the mentioned companies, this is a time to be particularly cautious. Carefully verify the sender of incoming emails, text messages, and phone calls. Be skeptical of messages that appear to be from your company or manager and ask for sensitive information or prompt you to click a link. Attackers can create highly convincing phishing scenarios using your leaked title and contact information.
For corporate security teams, this incident is a reminder of the importance of a proactive security posture. It is critical to regularly review access controls and administrator accounts, especially in Azure and other cloud platforms. Implementing more secure MFA methods, such as number matching instead of simple “approve/deny” notifications, adds an effective layer of defense against MFA fatigue attacks. Furthermore, continuous monitoring of accounts for abnormal login activity is necessary to detect a potential breach. It is always a good idea to see if your personal data has been exposed in other breaches. You can use a Data Breach Search tool for this purpose. Also, staying informed about the latest developments in the cybersecurity world by following reliable Data Breach News sources helps you prepare for future threats.
What the Companies Are Saying
The companies at the center of the allegations are trying to control the situation by issuing statements. In a notification to the National Stock Exchange of India, Tata Consultancy Services (TCS) stated that they investigated the alleged breach but found “no credible evidence of a breach of TCS systems or customer environments.” The company emphasized that the information for sale is at least four years old and contains only basic employee information. TCS also added that they have had strong safeguards against techniques like password spraying and MFA fatigue for more than two years and that their current defense mechanisms remain effective.
A similar statement came from a Gap Inc. spokesperson. The spokesperson said that the company found no evidence of a breach. Additionally, the data offered for sale is “limited in scope, non-sensitive and dated back to several years ago.” The Gap Inc. representative concluded, “Notably, there is no evidence to suggest that our corporate systems have been compromised,” implying the claims are unfounded. Other companies have not yet made official public statements. However, the existing statements indicate that at least some of the hacker's claims are unverified and that the data may not be current.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.