Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor is selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations.
Using the moniker ‘TheHatman’, the threat actor has been offering millions of records apparently stolen from well-known brands such as McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.
According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials.
The data contains internal employee directories that, based on the identified email addresses and field names that match Azure directory exports, appear legitimate, Hudson Rock says.
The McDonald’s dump is the largest, containing over 1.7 million records, followed by the TCS dataset, with 800,000 records, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000.
“Across all the affected tenant dumps, the leaked fields consistently include foundational corporate directory attributes,” Hudson Rock says.
Advertisement....
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE