Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.
Intelligence analysis by Llama

A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. The databases contain employee records, including names, email addresses, job titles, phone numbers, and postal addresses.
Imagine someone breaking into a company's computer system and stealing employee information, like names, email addresses, and job titles. This is what happened to several big companies, and the person who did it is selling the stolen information online.
Analysis
The Scope of the Breach
The threat actor claims to have 3.64 million data records, with the most recent breach posted on Sunday, containing an alleged 1.7 million employee records from McDonald's. The data includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records.
The Attack Vector
TheHatman says that the information includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records. The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector.
The Companies Affected
The companies affected by the breach include McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. The data dumps also contain service accounts and the names of global administrators, which could facilitate social engineering and spearphishing attacks.
The Implications of the Breach
The breach highlights the importance of strong security measures, including multi-factor authentication and regular security audits, to prevent such attacks. It also underscores the need for companies to regularly review their defenses and ensure that they are effective in preventing such attacks.
Key points
- A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies.
- The databases contain employee records, including names, email addresses, job titles, phone numbers, and postal addresses.
- The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector.
- The companies affected by the breach include McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl.
If the companies affected by the breach take immediate action to strengthen their security measures, they may be able to prevent similar attacks in the future. Additionally, the breach may lead to increased awareness and education about the importance of security and the need for regular security audits.
The breach may lead to significant financial losses for the companies affected, as well as damage to their reputation. Additionally, the stolen information could be used for social engineering and spearphishing attacks, which could compromise the security of other companies and individuals.



