A single threat actor appears to be quietly working through the corporate directories of some of the world’s biggest employers. Operating under the handle TheHatman, the seller has spent the past week listing internal Azure Active Directory exports from nine Fortune 500 organizations on dark-web forums — a haul that, by outside estimates, adds up to well over 3.6 million individual employee records.
Who’s Affected
The list of targeted companies spans retail, telecom, IT services, and hospitality, suggesting the campaign was opportunistic rather than aimed at a single sector. Reported exposure figures include:
- McDonald’s Corporation — roughly 1.7 million records
- Tata Consultancy Services (TCS) — around 800,000 records
- Vodafone — approximately 425,000 records
- HCL Technologies — about 250,000 records
- InterContinental Hotels Group — roughly 185,000 records
- Kyndryl — 170,000 records
- Gap Inc. — 80,000 records
- Hexaware Technologies — 20,000 records
- Wyndham Hotels — 9,000 records
What’s in the Stolen Data
This isn’t just a list of email addresses. Researchers at Hudson Rock, who reviewed samples of the leaked material, say the datasets carry the structural fingerprints of genuine Azure directory exports — matching corporate email domains and field layouts that would be difficult to fabricate. The records reportedly include full names, corporate email addresses, phone numbers and physical addresses, employee IDs, job titles and departments, manager assignments and full reporting hierarchies, and — most concerning — service account credentials and lists of Global Administrator accounts.
That last category is what elevates this from an embarrassing leak to an active operational risk. Directory data showing exactly who reports to whom, combined with valid administrator account listings, gives follow-on attackers a ready-made blueprint for impersonating IT staff or senior managers.
How the Credentials Were Likely Stolen
The exact intrusion path differs by victim, but Hudson Rock’s research points squarely at infostealer malware as the common thread. Investigators say they traced compromised Azure credentials linked to infostealer infections back to machines at TCS, Gap Inc., HCL Technologies, and Kyndryl. In one particularly striking case, a single infected device was found holding dozens of corporate credentials alongside hundreds of live session cookies — including a direct route into a Kyndryl Azure Active Directory account, no password needed.
Beyond infostealers, researchers flagged several other plausible contributing factors across the affected organizations: phishing campaigns that yielded administrative access, inconsistent or weak multi-factor authentication enforcement, and overly permissive third-party API integrations connected to Azure tenants.
Why Directory Data Matters More Than It Looks
Leaked passwords get reset. Leaked org charts don’t expire. With accurate reporting structures and manager assignments in hand, attackers gain everything they need to run convincing business email compromise schemes, craft spear-phishing lures that reference a target’s actual manager by name, or plan ransomware intrusions using an insider’s-eye view of who holds administrative access. Security teams should treat this kind of directory leak as an ongoing threat multiplier rather than a one-time exposure.
What Organizations Should Do
- Treat any device with infostealer indicators as fully compromised — rotate all credentials and invalidate active session cookies, not just passwords.
- Enforce phishing-resistant MFA (passkeys or hardware keys) for all Azure AD/Entra ID accounts, with particular urgency for Global Administrator roles.
- Audit third-party API integrations connected to Azure AD for excessive permissions.
- Monitor for spear-phishing attempts that reference accurate internal reporting structures — a strong sign the sender has access to leaked directory data.
- Assume any employee directory data sold once will be resold and recombined with other breaches over time.
None of the named companies have publicly commented on the claims at the time of writing. Given the scale and the presence of administrator-level credentials in the leaked sets, further disclosures — or follow-on attacks against these organizations — would not be surprising.
Leave a Reply