Massive Data Exposure Alleged by Hacker
A cybercriminal operating under the alias "TheHatman" has surfaced on dark web forums, claiming to have infiltrated the Azure and Entra environments of several major global corporations. The hacker asserts that these breaches were facilitated through the use of compromised login credentials, leading to the exposure of millions of sensitive employee records.
List of Impacted Organizations
According to the claims made by the threat actor, the following companies have been affected by the data theft:
- McDonald's Corporation: 1,700,000 records
- TCS (Tata Consultancy Services): 800,000 records
- Vodafone: 425,000 records
- HCL Technologies: 250,000 records
- InterContinental Hotels Group (IHG): 185,000 records
- Kyndryl: 170,000 records
- Gap Inc.: 80,000 records
- Hexaware Technologies: 20,000 records
- Wyndham Hotels: 9,000 records
Security Analysis and Potential Risks
Experts from Cybernews conducted an analysis of the data samples available on the dark web. Their findings suggest that the files are consistent with official Azure directory exports, containing detailed information such as employee names, contact details, job titles, department affiliations, and privileged account records.
While this data may appear to be standard corporate information, security analysts warn that it poses a significant threat. Access to such details allows attackers to conduct sophisticated social engineering campaigns. As noted by security researchers, "Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing ransomware, or making a fraudulent wire transaction."
Corporate Responses and Investigations
Many of the targeted organizations have responded to the claims, with several suggesting that the data is not the result of a current system compromise. Gap Inc. stated that they have found no evidence of a recent breach and believe the information is dated. Similarly, Tata Consultancy Services (TCS) reported to the Indian National Stock Exchange that their investigation found no signs of a current system intrusion, describing the data as "more than four years old."
Diverging Expert Opinions
Despite corporate denials, some cybersecurity firms remain skeptical of the dismissal. Researchers at Hudson Rock argue that the scale of the breach indicates the use of infostealer malware to harvest credentials, rather than standard password-spraying techniques. They maintain that the stolen data is "likely highly authentic" and remains a dangerous asset, regardless of its age.
