← All security news

A Credential-Theft Campaign Is Selling Millions of Azure Employee Records

A Microsoft Azure tenant panel with a directory of employee cards, one card breaking free and spilling its contents toward a dark marketplace listing, representing corporate employee data harvested from Azure tenants and offered for sale

A seller going by "TheHatman" has spent the past few weeks listing employee data lifted from Microsoft Azure and Entra ID tenants at a string of large companies, and the campaign grew again over the weekend. The claimed total now sits above 3.6 million records across nine organisations, led by McDonald's (over 1.7 million), Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware and Wyndham Hotels. What's on offer is directory-style data — names, corporate email addresses, job titles, phone numbers, employee IDs, and in some tenants service-account and privileged-account details — not customer records or plaintext passwords.

The seller attributes the access to compromised credentials, and researchers tracking the listings point to password spraying paired with MFA-fatigue prompts (repeatedly pushing an approval request until someone taps "approve" by mistake or habit) as the likely route in for at least some of the affected tenants. Not every claim has held up under scrutiny: Tata Consultancy Services says its own review found no evidence of a breach and that the sample resembles a stale internal export roughly four years old, while a threat-intelligence firm reviewing the data separately rated it authentic with high confidence. Treat the 3.6 million figure as the seller's own claim rather than a confirmed count — the technique behind it is well understood either way and worth acting on regardless of exactly how many records are real.

What this means for your business

  • If your organisation runs on Microsoft 365 or Azure, check that MFA approvals use number-matching or a passkey/FIDO2 key rather than a plain "approve/deny" push — that single setting is what blunts most MFA-fatigue attacks.
  • Ask whoever manages your Entra ID/Azure AD tenant whether sign-in risk policies are set to challenge or block password-spray patterns (many failed logins across many accounts from one source), rather than relying on per-account lockout alone.
  • Directory data like names, titles and phone numbers is exactly what fuels a convincing "IT helpdesk needs you to reset this" phishing message. A short reminder to staff about verifying unexpected password-reset or approval requests is worth sending this week, whether or not your organisation was named.

If one of the named companies is a vendor of yours, there's no need to alert your own customers yet — the claims are still being verified company by company. Worth keeping an eye on their public statements before repeating the headline number anywhere.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, The Register, SecurityWeek