Crook hawks millions of records allegedly plundered from corporate Azure tenants
A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services.
The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name "TheHatman," according to research published by Hudson Rock.
McDonald's accounts for the largest alleged dataset on TheHatman's shopping list, with 1.7 million records purportedly up for grabs.
Another 800,000 records supposedly come from Tata Consultancy Services, 425,000 from Vodafone, and 250,000 from HCL Technologies, with IHG Hotels & Resorts, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts rounding out the haul.
Hudson Rock assessed the data as "highly likely authentic," citing corporate email addresses and structures consistent with exports from Microsoft Azure directory services.
The records allegedly contain considerably more than names and work email addresses.
Samples reviewed by the security shop reportedly include phone numbers, physical addresses, employee IDs, job titles, departments, office locations, reporting structures, group memberships, and service account details.
Some records also reportedly identify accounts with Global Administrator privileges, potentially handing attackers a useful map of whom to target next.
Even if the passwords aren't included, knowing who holds the keys to the kingdom makes for a handy phishing shortlist.
How TheHatman allegedly obtained the information remains unclear.
The attacker claims to have used compromised credentials, but Hudson Rock could not independently establish the initial access vector.
It floated several possibilities, including credentials or session cookies stolen by infostealer malware, phishing, weak or absent multifactor authentication, and overly permissive third-party applications.
Hudson Rock said its infostealer database contained compromised Microsoft cloud credentials associated with most of the named companies, although it could not link those credentials to TheHatman's alleged access.
"Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure," said Hudson Rock.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.