A threat actor is offering millions of alleged Azure account records for sale, claiming they came from the Microsoft cloud tenants of several major companies. The seller says compromised credentials provided access to employee directories and internal account information.

The claims have not been independently verified. At least two named companies, Tata Consultancy Services and Gap Inc., say their investigations found no evidence that their systems were breached.

Hacker advertises employee databases

The seller, who uses the alias TheHatman, began advertising the data in late July. The posts claim to include records connected to companies such as McDonald’s, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels, Gap Inc. and Kyndryl.

In total, the actor claims to hold roughly 3.64 million Azure account records.

The largest alleged database reportedly contains more than 1.7 million McDonald’s employee records. The seller describes it as an internal employee dump taken from an Azure tenant using compromised credentials.

The advertised data allegedly includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts and other tenant account details.

Companies dispute breach claims

Tata Consultancy Services says it investigated the allegations and found no credible evidence of a breach affecting its systems or customer environments.

The company said the data appeared to be at least four years old and contained only basic employee information. It also said its protections against password spraying and multi-factor authentication fatigue attacks have been in place for more than two years.

Gap Inc. also said it found no evidence that its corporate systems were compromised. A company spokesperson described the advertised information as limited, non-sensitive and several years old.

Other companies named by the seller had not publicly commented at the time of publication.

Advertised records cover several organisations

The threat actor claims the data includes the following alleged datasets:

CompanyClaimed records
McDonald’s1.7 million+
Tata Consultancy Services800,000+
Vodafone425,000+
HCL Technologies250,000+
InterContinental Hotels185,000+
Kyndryl170,000+
Gap Inc.80,000+
Hexaware20,000+
Wyndham Hotels9,000+

TheHatman reportedly shared sample files with potential buyers so they could assess the data.

Directory data could support phishing attacks

Cybersecurity researchers who reviewed the samples said the datasets appear to contain corporate directory information, including active domains and tenant-specific cloud structures.

The records may also include service accounts and the names of global administrators. Even if the information is old, it could help criminals build convincing phishing or social-engineering campaigns against employees.

Researchers have expressed confidence that at least some of the data is authentic. However, the initial access method and the process used to remove the Azure account records remain unclear.

Organisations listed in the alleged dumps should remain alert for password-spraying attempts, MFA fatigue attacks and targeted phishing campaigns.


0 responses to “Hacker Claims 3.6 Million Azure Account Records Stolen From Major Companies”