Skip to content
Tech News
← Back to articles

Hacker claims 3.6 million Azure account records stolen from major companies

read original more articles
Why This Matters

A threat actor is selling stolen employee data from multiple Fortune 500 companies, including McDonald's and Tata Consultancy, after gaining access through compromised credentials on Microsoft Azure. This breach highlights ongoing vulnerabilities in cloud security and the importance of robust authentication measures. The incident underscores the need for organizations to strengthen their defenses against credential-based attacks to protect sensitive employee information.

Key Takeaways

A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.

​Starting July 31st, multiple posts from someone using the alias “TheHatman” advertised data dumps from major organizations, including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl.

In total, the threat actor claims to have 3.64 million data records, with the most recent breach posted on Sunday, containing an alleged 1.7 million employee records from McDonalds.

“I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” the threat actor says in the post.

TheHatman says that the information includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records.

Cybercriminal advertising McDonald's database with employee records

source: BleepingComputer

The second-largest data dump advertised is allegedly stolen from Tata Consultancy: an Azure dump with more than 800,000 employee records “downloaded directly from Azure Tenant using compromised credentials,” the cybercriminal states.

However, in a notification to the National Stock Exchange of India, Tata says it investigated the alleged breach and found no “credible evidence of a breach of TCS systems or customer environments."

The company states that the details appear to be at least four years old and include only basic employee information.

... continue reading