← All stories
● Covered by 1 source · 1 reportHigh impact1 negative

Threat Actor Sells Data Stolen from Fortune 500 Azure Tenants

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Threat actor 'TheHatman' is selling data from Fortune 500 Azure tenants.
  • Data includes employee directories, service accounts, and privileged account records.
  • Exfiltration likely occurred via leaked credentials from infostealer campaigns.
  • Affected companies include McDonald's, TCS, Vodafone, and IHG.

Data Theft Campaign Targets Fortune 500 Companies

A threat actor operating under the moniker 'TheHatman' is offering for sale data purportedly stolen directly from the Azure tenants of multiple Fortune 500 organizations. The data includes millions of records from well-known brands such as McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.

Exfiltrated Data Details and Source

The threat actor claims the data was exfiltrated from Azure/Entra instances using leaked credentials. Hudson Rock states that the data appears legitimate, based on identified email addresses and field names matching Azure directory exports. The McDonald’s dump is the largest with over 1.7 million records, followed by TCS with 800,000, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000 records.

The exfiltrated information consistently includes foundational corporate directory attributes such as employee names, corporate email addresses, physical addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, and highly privileged account records.

Implications for Affected Organizations

The exposure of service accounts and global admin names is particularly concerning, as it provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations. Hudson Rock suggests that credentials compromised in a targeted infostealer campaign were likely used for the data exfiltration, noting that stolen credentials linked to most affected organizations were identified.

The stolen data poses an immediate threat by allowing attackers to map internal reporting structures and identify high-value targets, enabling them to launch convincing spear-phishing and business email compromise (BEC) attacks against the victim organizations.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 13 stories · Aug 17

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A threat actor named 'TheHatman' is selling data allegedly exfiltrated from the Azure tenants of several Fortune 500 companies, including McDonald's and TCS. The stolen information, which includes employee directories and highly privileged account records, poses a significant risk for targeted attacks like spear-phishing and business email compromise.