Cybersecurity

Hacker Offers 3.64 Million Azure Account Records Belonging to Major Companies

An attacker named TheHatman claims to have stolen 3.64 million employee and corporate account records from Microsoft Azure environments belonging to major companies and is offering them for sale. BleepingComputer was unable to independently verify the authenticity of the data, while Tata Consultancy Services and Gap Inc. denied finding evidence that their systems had been breached.

2026-08-17
3 min read
9 views
فريق تحرير certi.news
Hacker Offers 3.64 Million Azure Account Records Belonging to Major Companies

A cyber attacker known as TheHatman is offering databases that he claims to have stolen from Microsoft Azure environments belonging to several major companies, alleging that they contain a total of 3.64 million records. The list includes data attributed to McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Kyndryl, and other companies.

Posts associated with these offers began on July 31, with the most recent advertising a database allegedly containing more than 1.7 million McDonald’s employee records. According to the attacker’s description, the data was downloaded directly from an Azure tenant using compromised credentials.

What data is being offered?

TheHatman says the records include employees’ names, identifiers, email addresses, job titles, phone numbers, and postal addresses, along with service accounts and other records associated with corporate tenants. The attacker also provided samples from each database to prospective buyers to verify its contents.

The advertised offers include more than 800,000 records attributed to Tata Consultancy Services, 425,000 records attributed to Vodafone, 250,000 attributed to HCL Technologies, 185,000 attributed to InterContinental Hotels, and 170,000 attributed to Kyndryl, along with smaller databases belonging to Wyndham Hotels and Hexaware.

Companies question whether a breach occurred

Tata Consultancy Services said in a notice to the National Stock Exchange of India that it investigated the claim and found no “credible evidence” of a breach of its systems or customer environments. It added that the data appears to be old, with some of it dating back at least four years, and that it is limited to basic employee information. The company also said the attacker claimed to have used password spraying and MFA fatigue as methods of access, emphasizing that it has had strong protections against these techniques for more than two years and that a review of its defenses showed they remain effective.

Gap Inc., for its part, said it found no evidence that its systems had been breached and that the offered data was limited, non-sensitive, and several years old. As of the report’s publication, the other companies had not provided comments.

Why does this claim matter?

Threat intelligence company Hudson Rock analyzed the samples and said the data contains basic attributes of corporate directories, including active domains and structures specific to .onmicrosoft.com Azure tenants. It also pointed to the presence of service accounts and global administrator names, details that could assist in social engineering and targeted phishing attacks.

However, Hudson Rock said the access path and method used to extract the data remain unknown, while BleepingComputer was unable to independently verify the authenticity of the leaks. Therefore, the offering of the data or the presence of samples does not prove that a recent breach affected all the companies mentioned, particularly given that some organizations have confirmed that the information is old or non-sensitive. The clearest conclusion at present is that corporate directory data, even when it does not contain direct secrets, may give attackers a useful map for targeting employees and highly privileged accounts.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news