Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

infostealersinfostealersinfostealersA threat actor calling themselves "TheHatman" has been selling massive internal employee directories stolen from several Fortune 500 companies, in what cybersecurity firm Hudson Rock describes as a large-scale Azure exfiltration campaign that unfolded over the past week.
The stolen data reportedly includes employee directories from McDonald's (approximately 1.7 million records), Tata Consultancy Services (800,000 records), Vodafone (425,000 records), HCL Technologies (250,000 records), InterContinental Hotels Group (185,000 records), Kyndryl (170,000 records), Gap The Gap, Inc. (80,000 records), Hexaware Technologies (20,000 records), and Wyndham Hotels (9,000 records), according to Hudson Rock's analysis published on its Infostealers.com research blog.infostealers
The actor claims the directories were extracted directly from the organizations' Azure and Entra identity portals using compromised credentials. The leaked data includes corporate email addresses, phone numbers, job titles, department structures, manager details, user group memberships, and — most critically — service account and global administrator records.cybersecuritynews+1
While the data appears authentic based on Hudson Rock's analysis of corporate email domains and field names matching standard Azure directory exports, the exact intrusion method has not been confirmed. Hudson Rock researchers said the campaign could stem from infostealer malware compromising employee session tokens, phishing campaigns that yielded administrative access, weak multi-factor authentication enforcement, or abuse of third-party integrations with excessive read privileges.infostealers
The firm noted it found compromised Azure credentials from infostealer infections linked to most of the affected companies, and assessed that the targeted nature of the campaign — hitting only large enterprises rather than a broad spectrum of organizations — suggests exploitation of stolen credentials rather than a systemic Azure vulnerability.infostealers
The exposure of internal organizational structures and privileged account details creates a roadmap for follow-on attacks, including business email compromise, spear-phishing, and targeted privilege escalation. The identification of global administrator accounts is particularly concerning for ransomware operators seeking high-value targets within enterprise environments.cybersecuritynews+1