What Happened
A threat actor operating under the alias TheHatman is selling data allegedly stolen from the Azure and Entra ID tenants of several Fortune 500 organizations, including McDonald’s, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels. Listings claim millions of records, including employee names, email addresses, phone numbers, job titles, and workplace addresses. The largest confirmed dataset, from McDonald’s, contains more than 1.7 million records, with TCS at 800,000, Vodafone at 425,000, HCL at 250,000, and IHG at 185,000. Threat intelligence firm Hudson Rock says the data appears legitimate based on matching email formats and field names consistent with genuine Azure directory exports. The actor has not disclosed a specific attack method, though researchers point to likely explanations including infostealer malware harvesting session tokens, phishing campaigns yielding administrative access, tenants lacking enforced multi-factor authentication, or a third-party integration with overly broad read permissions.
Why This Matters for Canadian Organizations
Microsoft Azure and Entra ID sit at the center of identity and access management for a large share of Canadian enterprises, government departments, and Crown corporations. This campaign shows how a single set of compromised credentials, whether stolen through malware, phishing, or a loosely scoped API integration, translates directly into bulk exfiltration of employee directory data at organizations with far more security resources than most. Canadian organizations subject to OSFI Guideline B-13 face explicit expectations around identity and access controls, and this incident underscores why MFA enforcement and least-privilege API permissions belong at the top of the priority list rather than being treated as optional hardening.
What to Do
Security teams should confirm MFA enforcement across all Azure and Entra accounts with no exceptions for service or admin accounts, audit third-party application permissions for unnecessarily broad directory read access, and monitor for anomalous Azure AD sign-in activity consistent with token theft. Coverage is available from SecurityWeek and The Register.






