Skip to content
Blog Post

Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others)

InfoStealers
5 min read
Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials

Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials

A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials.

Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants.

List of forum posts by TheHatman
A screenshot showing the extent of the threat actor’s posts on a dark web forum, listing multiple global enterprises.

Affected Organizations & Scope

The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics. Our researchers went over the data and it seems highly legitimate based on the corporate email addresses found, combined with field names perfectly matching standard Azure directory exports.

Here are the affected organizations and the staggering amount of records offered by the threat actor:

  • McDonald’s Corporation: ~1,700,000+ records
  • TCS (Tata Consultancy Services): ~800,000+ records
  • Vodafone: ~425,000+ records
  • HCL Technologies: ~250,000+ records
  • InterContinental Hotels Group (IHG): ~185,000+ records
  • Kyndryl: ~170,000+ records
  • Gap Inc.: ~80,000+ records
  • Hexaware Technologies: ~20,000+ records
  • Wyndham Hotels: ~9,000+ records
Threat actor advertising McDonald's data
The threat actor advertising 1.7 million McDonald’s employee records.
Threat actor advertising Vodafone data
Forum post offering 425,000 internal employee records from Vodafone.

Data Overview & Analysis

Across all the affected tenant dumps, the leaked fields consistently include foundational corporate directory attributes. By dissecting the provided samples, we can clearly see the structure of the exfiltrated data:

  • Core Identity & Contact: Full Name, corporate email addresses (including active domains and tenant-specific .onmicrosoft.com structures), phone numbers, and physical addresses.
  • Organizational Structure: Employee IDs, job titles, departments, notes, manager details, and direct reports.
  • Access & Group Mappings: User group memberships, service accounts, and highly privileged account records (such as Global Administrator listings).

The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations.

Snippet of leaked McDonald's data
A snippet of the leaked McDonald’s data, showing structured corporate directory attributes including DisplayName, UserPrincipalName, and EmployeeId.
Sample of Kyndryl data leak
Sample of the Kyndryl data leak, indicating detailed job roles, managers, and internal email structures.

Inconclusive Attack Vector

While the data is highly authentic, it is not conclusive how this campaign is being carried out. The threat actor specifically claims the data was downloaded “using compromised credentials.”

However, the exact intrusion vector remains unknown. This mass exfiltration could be the result of active Infostealer infections compromising employee session tokens, highly successful phishing campaigns yielding administrative access, a lack of strict Multi-Factor Authentication (MFA) on specific tenant portals, or potentially an abuse of a third-party API/Integration that had excessive read privileges across multiple environments. The sheer scale and speed of these dumps suggest a systematic, automated approach once initial access is achieved.

The Infostealer Connection

While we don’t have definitive confirmation as to which specific credentials were used to hack these organizations, Hudson Rock researchers were able to find compromised Azure credentials originating from Infostealer infections linked to most of the affected companies.

Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure. If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises.

Hudson Rock platform showing compromised TCS credentials
Hudson Rock’s cybercrime intelligence platform identifying compromised Azure Active Directory credentials belonging to an employee at TCS (Tata Consultancy Services), originating from a machine infected in India.
Hudson Rock platform showing compromised Gap Inc credentials
Evidence of compromised Microsoft credentials associated with a Gap Inc. corporate account, identified via an Infostealer infection.
Hudson Rock platform showing compromised HCL Technologies credentials
A compromised machine profile revealing stolen Azure Active Directory credentials for an HCL Technologies employee, highlighting the risk of password reuse.
Hudson Rock platform showing compromised Kyndryl credentials
Hudson Rock platform detailing a highly compromised machine containing dozens of corporate credentials and hundreds of sensitive cookies, including direct access to a Kyndryl Azure Active Directory account.

Real-World Risks and Weaponization of Directory Data

The exposure of massive internal corporate directories poses a severe and immediate threat to the affected enterprises. Hackers routinely weaponize this structured data to execute highly convincing Business Email Compromise (BEC) and spear-phishing campaigns. By understanding an organization’s exact reporting structure, departments, and job titles, attackers can easily impersonate managers or IT personnel to manipulate employees into approving fraudulent wire transfers or handing over multi-factor authentication (MFA) tokens.

Furthermore, the identification of service accounts and Global Administrators gives initial access brokers and ransomware operators a precise roadmap of high-value targets. To proactively defend against these intrusions, organizations must monitor for the initial infection vectors. By leveraging Hudson Rock’s cybercrime intelligence and our flagship platform, Cavalier, security teams can detect compromised employee, user, and third-party credentials originating from Infostealers before threat actors can exploit them to access critical infrastructure like Azure.

To learn more about how Hudson Rock protects companies from imminent intrusions caused by info-stealer infections of employees, partners, and users, as well as how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us, here:
https://www.hudsonrock.com/schedule-demo

We also provide access to various free cybercrime intelligence tools that you can find here:
www.hudsonrock.com/free-tools

Thanks for reading, Rock Hudson Rock!

Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock
Follow us on Twitter: https://www.twitter.com/RockHudsonRock

Continue reading

Related articles

Free Tools Check your exposure