Massive Data Exposure Alleged by Hacker

A cybercriminal identifying as "TheHatman" has surfaced on dark web forums, claiming to have exfiltrated millions of sensitive employee records from prominent global organizations. The hacker asserts that these breaches were facilitated by unauthorized access to Azure and Entra environments, utilizing compromised login credentials to target nearly a dozen large-scale enterprises.


Scope of the Affected Organizations

The list of companies purportedly affected by this incident includes major industry players. According to the hacker's claims, the volume of exposed records is substantial:

  • McDonald's Corporation: 1,700,000 records
  • TCS (Tata Consultancy Services): 800,000 records
  • Vodafone: 425,000 records
  • HCL Technologies: 250,000 records
  • InterContinental Hotels Group (IHG): 185,000 records
  • Kyndryl: 170,000 records
  • Gap Inc.: 80,000 records
  • Hexaware Technologies: 20,000 records
  • Wyndham Hotels: 9,000 records

Security Analysis and Potential Risks

Cybernews security analysts reviewed samples of the leaked data and confirmed that the files appear to be genuine Azure directory exports. The stolen information includes full names, email addresses, phone numbers, job titles, workplace IDs, and privileged account details.

Experts highlight that while this data may seem standard, it poses severe risks for corporate espionage and social engineering. "Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing ransomware, or making a fraudulent wire transaction," notes a recent security report. Such tactics effectively turn a data leak into a launching pad for complex financial fraud.


Company Responses and Disputed Claims

Many of the targeted organizations have pushed back against the severity of these allegations. Gap Inc. stated that after a preliminary investigation, they found no evidence of a direct system breach and believe the leaked data is outdated. Similarly, TCS reported to the Indian National Stock Exchange that they found no proof of a compromise, suggesting the exposed information is over four years old and primarily limited to non-sensitive employee details.


Expert Perspective on the Source

While companies maintain that the data is old and systems remain secure, security researchers at Hudson Rock offer a different perspective. They believe the breach originated from "infostealer" malware rather than systemic platform vulnerabilities. As the researchers stated: «Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure.» They further warned that regardless of the data's age, its authenticity makes it a potent tool for malicious actors.