Azure Cloud Data Breach Affects Major Companies
A threat actor used stolen credentials to pull millions of employee records from well-known brands

Key points
- A threat actor called 'TheHatman' claims to have stolen data from several Fortune 500 companies.
- McDonald's lost over 1.7 million records, the largest single batch taken.
- Stolen directory data gives attackers a map of internal reporting structures, making targeted phishing far easier.
- The credentials used were likely harvested through an infostealer campaign aimed specifically at these organisations.
A threat actor going by 'TheHatman' says they pulled millions of employee records directly from the cloud tenants of major companies including McDonald's, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. The method was straightforward: leaked credentials used against Microsoft's Azure cloud platform and its Entra identity service.
How did the hackers get in?
Credentials stolen through a targeted infostealer campaign appear to be the entry point. Hudson Rock, which analysed the leaked data, found stolen credentials tied to most of the named organisations and says the targeting pattern suggests a deliberate campaign rather than opportunistic scanning. The data's structure matches Azure directory exports closely enough that Hudson Rock considers it genuine.
What data was stolen?
McDonald's took the biggest hit at over 1.7 million records. The figures for others follow a steep drop-off.
| Company | Records Stolen |
|---|---|
| McDonald's | 1.7 million |
| TCS | 800,000 |
| Vodafone | 425,000 |
| HCL Technologies | 250,000 |
| IHG | 185,000 |
What makes this worse than a simple email leak is the depth of what was taken: employee IDs, phone numbers, job titles, manager relationships, group memberships, service accounts and records for highly privileged users. Hudson Rock flags service account exposure in particular, calling it "a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks."
Should employees be worried?
Yes, and not just because their names are out there. Knowing the internal hierarchy lets an attacker write a convincing message that appears to come from someone's actual manager. That's spear-phishing, meaning a targeted fake email crafted with real internal detail, and it's considerably harder to spot than a generic scam. Business email compromise, where attackers impersonate executives to authorise transfers or share credentials, becomes more viable the richer the directory data gets. We covered a spear-phishing attack that used new loader and backdoor tooling on 31 July that shows how far a well-prepared attacker can go once they're inside a network.
The honest read here is that none of the attack technique is novel. Leaked credentials plus a cloud directory equals a phishing kit: it's been the playbook for years. What's changed is the scale these campaigns now reach and the ease with which stolen infostealer logs turn into targeted access across dozens of enterprises at once.
Common questions
What is Azure?
Azure is Microsoft's cloud computing platform, which companies use to store data and manage who can access what, rather than running everything on their own servers.
What should I do if my company uses Azure?
Treat any unexpected email asking you to confirm access, reset credentials, or approve a payment with extra suspicion. Verify through a channel you already trust before acting.
Can my personal information be used against me?
Yes. Job title, manager name and work email together are enough for an attacker to write a message that looks entirely legitimate.



