Skip to content

TheHatman sells Azure/Entra directory data from McDonald’s, Vodafone and TCS

In brief: A hacker is selling Azure/Entra directory data from McDonald’s, TCS, Vodafone and other Fortune 500 companies, sourced from an infostealer campaign and containing details on global admin and service accounts.

A cybercriminal operating under the pseudonym “TheHatman” is offering employee directory data from Microsoft Azure and Entra instances of several Fortune 500 corporations for sale. According to security firm Hudson Rock, millions of records are affected, including information on privileged admin and service accounts.

According to research by Hudson Rock, the datasets offered for sale originate from internal company directories that were exfiltrated via compromised Azure and Entra tenants. McDonald’s is the most affected, with more than 1.7 million records, followed by IT services provider Tata Consultancy Services (TCS) with around 800,000 entries and telecommunications provider Vodafone with 425,000 records. Further leaks affect HCL Technologies (250,000), InterContinental Hotels Group (185,000), as well as Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels.

The exfiltrated data includes names, business email addresses, phone numbers, employee IDs, job titles, manager assignments and group memberships. The root cause is believed to be credentials stolen as part of an infostealer campaign, which were subsequently used to gain unauthorized access to the affected companies’ cloud tenants.

For CISOs, the exposure of information on service accounts and global admin roles is particularly relevant. Hudson Rock assesses this as “especially concerning, as it provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks.” The disclosed management hierarchies also make it easier for attackers to precisely select high-value targets for business email compromise fraud or fake executive messages.

Affected organizations and comparable entities should check whether employee credentials are circulating in infostealer logs, verify MFA enforcement for all accounts with Azure/Entra access, and specifically monitor service accounts and global admin accounts for unusual login activity. Since the datasets contain specific names and hierarchy structures, raising awareness among executives and their assistants about targeted phishing and BEC attempts in the coming weeks is also recommended.


Source: www.it-daily.net · Published August 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: