• Sources: Hudson Rock research, Reddit discussion
  • Summary: Hudson Rock reports an actor under the moniker TheHatman advertising Azure and Entra directory dumps on cybercrime forums over the past week: McDonald's about 1,700,000 records, TCS about 800,000, Vodafone about 425,000, HCL about 250,000, IHG about 185,000, Kyndryl about 170,000, Gap about 80,000, Hexaware about 20,000, and Wyndham about 9,000. The leaked fields are stated to include employee IDs, manager and direct-report structure, group memberships, service accounts, and Global Administrator listings. The intrusion vector is explicitly inconclusive, and Hudson Rock states it found compromised Azure credentials from infostealer infections linked to most of the affected companies and argues that the confinement to very large enterprises points away from a systemic Azure vulnerability. No affected versions apply, because the intrusion vector is stated as inconclusive and no product defect is claimed. This is vendor research from a company selling the detection product, no affected organisation has confirmed the exposure, and the record counts are the seller's own advertised figures.
  • Why it matters: A directory export naming service accounts and Global Administrators is a targeting list for spear-phishing and privilege escalation, not only a privacy exposure.
  • Follow-up: Watch for a statement from any of the nine named organisations.

send feedback on this story