Hacker claims to have stolen millions of Azure customer records from McDonald’s, Vodafone, Kyndryl, and others – here's what we know so far
TheHatman claims the data has been stolen from the victims' Azure and Entra tenants using compromised credentials
A hacker is advertising data allegedly stolen from an array of companies including McDonald's, Vodafone, Kyndryl, and more.
Researchers at HudsonRock said that the criminal, known as TheHatman, downloaded the databases directly from the organizations’ Azure or Entra portals, claiming to have done so through the use of compromised credentials.
Other victims include HCL Technologies, IHG Hotels & Resorts, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts.
"The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics," researchers said.
"Our researchers went over the data and it seems highly legitimate based on the corporate email addresses found, combined with field names perfectly matching standard Azure directory exports."
The data – which includes roughly 3.6 million records in total – appears to include full names, corporate email addresses, including active domains and tenant-specific .onmicrosoft.com structures, phone numbers, and physical addresses.
It also covers employee IDs, job titles, departments, notes, manager details, and direct reports, along with user group memberships, service accounts, and highly privileged account records such as Global Administrator listings.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations," HudsonRock said.
TheHatman's methods still unclear
Exact details on how the threat actor gained access to this trove of data remains unclear, according to researchers.
Possibilities include infostealer malware infections which compromised employee session tokens, phishing campaigns, or a lack of strict multi-factor authentication (MFA) on specific tenant portals.
Researchers also suggested it could be down to abuse of a third-party API that had excessive read privileges across multiple environments.
According to HudsonRock, the most likely explanation is a targeted exploitation of infostealer infections rather than a systemic zero-day vulnerability in Azure, as this would have hit a far broader range of victims.
Alleged victims react
Companies said to have been caught up in the breach have begun taking action.
TCS, for example, has filed a statement with India’s stock exchange, revealing that it hasn’t yet found any credible evidence of a breach of systems or customer environments.
"The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted," the statement reads.
ITPro approached the other aforementioned victims, but did not receive a response by time of publication.
Valuable credentials
Darren Williams, CEO and founder of BlackFog, said that if the claims are legitimate then this once again highlights the value of exposed credentials for cyber criminals.
These can often represent the keys to the castle for hackers, giving them sweeping access to enterprise environments.
“The reported use of leaked credentials to access Azure and Entra environments shows how valuable compromised identities have become to cyber criminals," he said.
"MFA, strong identity controls and employee awareness remain essential, but organizations must assume credentials can be compromised. These measures must be backed by technology that prevents sensitive data from being exfiltrated, even when attackers successfully gain access to the network.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
National Grid plans major works to accommodate London data centersNews The program includes new and upgraded substations, new cables, and reinforcement of existing overhead lines
-
The GitHub outage explainedNews An eight-hour GitHub outage saw an error rate of 50% for repo downloads and major disruption to Actions, APIs, and Copilot
-
Kyndryl and Vodafone Business collaborate on new cyber security servicesNews The expanded partnership aims to help Vodafone customers meet their regulatory compliance requirements
-
Kyndryl and Veeam unveil new global strategic allianceNews New cyber resiliency services aim to help enterprise customers drive business continuity and reduce operational costs
-
Vodafone sues UK government after missing out on £184m Foreign Office contractNews The company says the contract to supply secure communications to 532 British embassies was unfairly awarded to Fujitsu
-
Hackers steal nearly 2,000 Vodafone customer accountsNews Mobile operator blocks compromised accounts, urges customers to change passwords
-
Vodafone: "Big Data is a big problem for us"News Telco firm admits it is struggling with Big Data security
-
Ofcom "in talks" with Vodafone over police & NHS weekend call failuresNews Ofcom says it's urgently investigating outage after UK left without non-emergency access to Police and NHS
-
ICO and mobile networks join forces to cut spam text messagesNews EE, O2, Three, Vodafone have all signed up to the scheme that will rely on consumers reporting spam texts
-
BAE Systems and Vodafone partner for mobile security pushNews Companies sign five-year supplier and technology deal.