Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Fortune 500 Companies Hit in Azure Data Theft Campaign

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.

Microsoft Azure

A threat actor is selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations.

Using the moniker ‘TheHatman’, the threat actor has been offering millions of records apparently stolen from well-known brands such as McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.

According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials.

The data contains internal employee directories that, based on the identified email addresses and field names that match Azure directory exports, appear legitimate, Hudson Rock says.

The McDonald’s dump is the largest, containing over 1.7 million records, followed by the TCS dataset, with 800,000 records, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000.

“Across all the affected tenant dumps, the leaked fields consistently include foundational corporate directory attributes,” Hudson Rock says.

Advertisement. Scroll to continue reading.

The exfiltrated information includes employee names, corporate email addresses, addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, highly privileged account records, and more.

“The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations,” Hudson Rock notes.

According to the company, credentials compromised in a targeted infostealer campaign were likely used to exfiltrate the data. Not only did Hudson Rock identify stolen credentials linked to most of the affected organizations, but the victimology also suggests a targeted attack.

“The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics,” the company notes.

Hudson Rock also points out that the stolen data poses an immediate threat to the victim organizations, as it allows attackers to map internal reporting structures and high-value targets, and enables them to launch convincing spear-phishing and business email compromise (BEC) attacks.

Related: 1.6 Million Likely Impacted by RingCentral Data Breach

Related: 14,000 Trezor Customers Impacted by Data Breach at ShipMonk

Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Related: Massive Password Spray Campaign Targeting Azure CLI

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.