A threat actor is offering millions of alleged Azure account records for sale, claiming they came from the Microsoft cloud tenants of several major companies. The seller says compromised credentials provided access to employee directories and internal account information.
The claims have not been independently verified. At least two named companies, Tata Consultancy Services and Gap Inc., say their investigations found no evidence that their systems were breached.
Hacker advertises employee databases
The seller, who uses the alias TheHatman, began advertising the data in late July. The posts claim to include records connected to companies such as McDonald’s, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels, Gap Inc. and Kyndryl.
In total, the actor claims to hold roughly 3.64 million Azure account records.
The largest alleged database reportedly contains more than 1.7 million McDonald’s employee records. The seller describes it as an internal employee dump taken from an Azure tenant using compromised credentials.
The advertised data allegedly includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts and other tenant account details.
Companies dispute breach claims
Tata Consultancy Services says it investigated the allegations and found no credible evidence of a breach affecting its systems or customer environments.
The company said the data appeared to be at least four years old and contained only basic employee information. It also said its protections against password spraying and multi-factor authentication fatigue attacks have been in place for more than two years.
Gap Inc. also said it found no evidence that its corporate systems were compromised. A company spokesperson described the advertised information as limited, non-sensitive and several years old.
Other companies named by the seller had not publicly commented at the time of publication.
Advertised records cover several organisations
The threat actor claims the data includes the following alleged datasets:
| Company | Claimed records |
|---|---|
| McDonald’s | 1.7 million+ |
| Tata Consultancy Services | 800,000+ |
| Vodafone | 425,000+ |
| HCL Technologies | 250,000+ |
| InterContinental Hotels | 185,000+ |
| Kyndryl | 170,000+ |
| Gap Inc. | 80,000+ |
| Hexaware | 20,000+ |
| Wyndham Hotels | 9,000+ |
TheHatman reportedly shared sample files with potential buyers so they could assess the data.
Directory data could support phishing attacks
Cybersecurity researchers who reviewed the samples said the datasets appear to contain corporate directory information, including active domains and tenant-specific cloud structures.
The records may also include service accounts and the names of global administrators. Even if the information is old, it could help criminals build convincing phishing or social-engineering campaigns against employees.
Researchers have expressed confidence that at least some of the data is authentic. However, the initial access method and the process used to remove the Azure account records remain unclear.
Organisations listed in the alleged dumps should remain alert for password-spraying attempts, MFA fatigue attacks and targeted phishing campaigns.


0 responses to “Hacker Claims 3.6 Million Azure Account Records Stolen From Major Companies”