Azure Tenant Data Claims Put Fortune 500 Directories In Focus
SecurityWeek reported that TheHatman is selling millions of records allegedly taken from Azure and Entra tenants, while Hudson Rock tied the likely access path to stolen credentials.

A data broker's Azure tenant claims have moved a credential-theft incident into enterprise cloud directories, SecurityWeek reported, after a threat actor offered millions of records allegedly taken from companies including McDonald's, Tata Consultancy Services and Vodafone.
The actor, using the name TheHatman, listed datasets tied to McDonald's Corporation, TCS, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc, Hexaware Technologies and Wyndham Hotels.
The claimed access path was Azure and Entra instances reached through leaked credentials.
Directory Records Turn Credentials Into Target Maps
Hudson Rock assessed that the exposed material appeared legitimate because the email addresses and field names matched Azure directory exports.
The largest claimed dataset was McDonald's at more than 1.7 million records, followed by TCS at 800,000 records, with Vodafone, HCL Technologies and IHG also named among the larger sets.
The listed fields include employee names, corporate email addresses, phone numbers, employee IDs, job titles, manager details, group membership, service accounts and highly privileged account records.
That combination changes the risk from a contact-list leak into a map of reporting lines, administrative targets and technical accounts that can support follow-on phishing or privilege escalation.
Infostealer Credentials Remain The Suspected Entry Point
Hudson Rock tied the likely access path to credentials compromised in a targeted infostealer campaign.
Stolen logins linked to most affected organizations and the spread of victims across IT services, hospitality, telecommunications, retail and logistics led the company to assess the campaign as targeted rather than random resale of old breach data.
For cloud-security teams, the practical response starts with identity evidence rather than public breach claims.
Tenant administrators need to check risky sign-ins, service-account activity, new group memberships, privileged-role changes and directory export behavior around the affected accounts.
The unresolved issue is whether each named organization can confirm the claimed tenant exposure and disable the stolen credential paths before the directory data is converted into spear-phishing, business email compromise or privilege-escalation attempts.




















