A cybercriminal calling themselves "TheHatman" claims to have stolen millions of employee records from the Microsoft Azure environments of nine major corporations, including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, according to research published by Hudson Rock. The attacker is advertising the data for sale, with the alleged breach spanning Fortune 500-level enterprises. Hudson Rock assessed the records as "highly likely authentic," pointing to corporate email addresses and structures that match exports from Microsoft Azure directory services.

The advertised haul includes approximately 3.4 million employee records across the nine organizations. McDonald's accounts for the largest share, with 1.7 million records allegedly available, while Tata Consultancy Services represents another 800,000 records. Vodafone's alleged dataset contains 425,000 records, and HCL Technologies accounts for 250,000. The remaining companies—IHG Hotels & Resorts, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts—make up the rest. The stolen information reportedly goes well beyond basic contact details, with samples containing phone numbers, physical addresses, employee IDs, job titles, departments, office locations, reporting structures, group memberships, and service account details. Some records also allegedly identify accounts with Global Administrator privileges, potentially providing attackers with a roadmap of high-value targets for follow-on phishing campaigns.

TheHatman claims to have used compromised credentials to extract the information, though Hudson Rock couldn't independently verify the initial access method. The security firm suggested several possibilities, including credentials or session cookies harvested by infostealer malware, phishing, weak or missing multifactor authentication, and overly permissive third-party applications. Hudson Rock noted that its infostealer database held compromised Microsoft cloud credentials linked to most of the named organizations, though it couldn't connect those credentials directly to TheHatman's alleged breach. "Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure," Hudson Rock stated, reasoning that a widespread vulnerability would affect a broader range of organizations, including smaller businesses. Tata Services told the Indian stock exchange that it "has not found any credible evidence of a breach of TCS systems or customer environments," describing the information as more than four years old and limited to basic employee details.

How TheHatman allegedly extracted data from nine separate corporate directories remains unexplained, with no organization confirming a breach. The attacker claims to have used password spray and multifactor authentication fatigue as attack methods, though Tata Services said it has maintained strong defenses against such techniques for over two years. The Register contacted all named organizations and Microsoft to ask whether breaches occurred, whether the advertised data is authentic, and how any unauthorized access happened, but most have not responded. The incident highlights the persistent risk that compromised credentials pose to cloud environments, even at large enterprises with substantial security budgets. For decision-makers evaluating cloud security postures, the alleged breach underscores the challenge of defending against attacks that exploit human vulnerabilities rather than technical flaws, raising questions about whether current authentication strategies sufficiently account for the maturity of credential-theft ecosystems.