Executive Summary
A critical Azure exfiltration campaign has been identified, targeting major global enterprises including McDonald’s Corporation, Vodafone, Kyndryl, TCS, HCL Technologies, InterContinental Hotels Group (IHG), Gap Inc., Hexaware Technologies, and Wyndham Hotels. The campaign, attributed to a threat actor known as TheHatman, involves the mass theft and sale of internal employee directories directly extracted from organizations’ Azure/Entra portals using compromised credentials. The authenticity of the leaked data is supported by the structure and content of the dumps, which match standard Azure directory exports and contain legitimate corporate email addresses. The attack vector is not conclusively determined, but evidence strongly suggests the use of infostealer malware to harvest credentials, with possible contributions from phishing and insufficient multi-factor authentication (MFA) enforcement. The exposure of privileged accounts and organizational structure significantly increases the risk of downstream attacks such as Business Email Compromise (BEC), spear-phishing, and ransomware. No evidence of an Azure platform vulnerability or zero-day has been found; the campaign relies on credential theft and abuse of legitimate access. All findings are based on the primary technical analysis published by InfoStealers and Hudson Rock on August 16, 2026.
Technical Information
The campaign centers on the exfiltration of large-scale internal employee directories from Azure/Entra portals. The threat actor, TheHatman, claims to have accessed and downloaded these directories using compromised credentials, which were then offered for sale on cybercrime forums. The affected organizations span IT services, hospitality, telecommunications, retail, and logistics sectors, with record counts ranging from approximately 9,000 to over 1.7 million per organization.
The exfiltrated data includes core identity and contact information such as full names, corporate email addresses (including tenant-specific .onmicrosoft.com domains), phone numbers, and physical addresses. Organizational structure details such as employee IDs, job titles, departments, manager information, and direct reports are also present. Critically, the dumps contain user group memberships, service accounts, and highly privileged account records, including Global Administrator listings.
The exposure of service accounts and privileged users provides attackers with a roadmap for subsequent social engineering, spear-phishing, and privilege escalation attacks. The structured nature of the data enables highly targeted Business Email Compromise (BEC) and impersonation campaigns, as attackers can accurately mimic internal reporting lines and IT personnel.
The initial access vector remains inconclusive. The threat actor claims the data was obtained using compromised credentials, but the specific method of credential compromise is not confirmed. Technical analysis suggests several plausible vectors:
The most likely scenario is the use of infostealer malware on employee endpoints, which harvests browser-stored credentials and session tokens for Azure and other cloud services. This is supported by Hudson Rock’s discovery of compromised Azure credentials linked to infostealer infections in most affected companies. Other possible vectors include highly successful phishing campaigns targeting privileged users, lack of strict MFA enforcement on Azure/Entra portals, or abuse of third-party integrations with excessive read privileges.
The campaign demonstrates a high degree of automation and scale, with rapid, multi-tenant data dumps suggesting systematic exploitation once initial access is achieved. The focus on Fortune 500-level organizations, rather than small and medium businesses, indicates targeted credential harvesting and resale, likely prioritizing high-value access brokers and ransomware operators.
Mapped to the MITRE ATT&CK framework, the campaign involves the following techniques:
- T1078: Valid Accounts – Use of stolen credentials to access Azure/Entra portals (high confidence, based on actor claims and credential-based access patterns).
- T1555: Credentials from Password Stores – Infostealer malware harvesting credentials from infected endpoints (medium confidence, based on Hudson Rock’s evidence).
- T1566: Phishing – Possible initial access vector for credential theft (low confidence, circumstantial evidence).
- T1071: Application Layer Protocol – Use of legitimate Azure/Entra web interfaces or APIs for data exfiltration (medium confidence).
- T1087: Account Discovery – Enumeration of user/group memberships and privileged accounts within Azure tenants (high confidence).
- T1114: Email Collection – Exfiltration of corporate email addresses and directory data (high confidence).
No specific infostealer malware family is named in the report, but commodity infostealers such as RedLine, Raccoon, and Vidar are known to target browser-stored credentials and session tokens for Microsoft cloud services. There is no evidence of custom malware or exploitation of Azure zero-days; the campaign relies on credential theft and abuse of legitimate access.
The threat actor TheHatman does not have a known history of previous high-profile campaigns or links to advanced persistent threat (APT) groups. The scale and automation of this Azure-specific campaign are unprecedented, representing a significant escalation in the weaponization of infostealer-derived credentials for cloud infrastructure attacks.
Affected Versions & Timeline
The campaign affects organizations using Azure/Entra portals, with no evidence of a specific software version vulnerability. The attack leverages compromised credentials rather than exploiting a flaw in the Azure platform itself. The earliest public evidence of the campaign appeared in mid-August 2026, with the primary technical analysis published on August 16, 2026. The campaign is ongoing, with new data dumps and victim organizations continuing to surface on cybercrime forums.
Threat Activity
The threat actor TheHatman has been actively selling massive internal employee directories from Fortune 500 companies on cybercrime forums. The data is highly structured and matches standard Azure directory exports, increasing its value for downstream attacks. The campaign’s focus on large enterprises across IT services, hospitality, telecommunications, retail, and logistics sectors suggests a deliberate targeting of organizations with high-value data and privileged access.
The weaponization of the leaked directory data enables attackers to conduct highly convincing BEC and spear-phishing campaigns, impersonate managers or IT personnel, and manipulate employees into approving fraudulent transactions or disclosing MFA tokens. The identification of service accounts and Global Administrators provides initial access brokers and ransomware operators with precise targets for further exploitation.
Attribution to TheHatman is based on forum postings and actor self-identification, with medium confidence. The initial access vector is attributed to infostealer malware based on credential telemetry from Hudson Rock, but no specific malware family is named. There is no evidence of Azure platform vulnerabilities or zero-days; the campaign relies on credential theft and abuse of legitimate access.
Mitigation & Workarounds
The following mitigation steps are prioritized by severity:
Critical: Immediately enforce strict Multi-Factor Authentication (MFA) for all users, especially privileged and administrative accounts, on all Azure/Entra portals. Review and revoke any suspicious or unused sessions and credentials.
High: Conduct a comprehensive audit of all privileged accounts, service accounts, and group memberships within your Azure tenant. Monitor for unusual access patterns, especially large-scale directory exports or API calls.
High: Deploy endpoint detection and response (EDR) solutions to identify and remediate infostealer malware infections on employee devices. Regularly scan for compromised credentials using threat intelligence feeds and credential monitoring services.
Medium: Review and restrict third-party integrations and APIs with access to Azure directory data. Ensure that all integrations follow the principle of least privilege and are subject to regular security reviews.
Medium: Educate employees about phishing risks, credential theft, and social engineering tactics. Conduct regular security awareness training and simulated phishing exercises.
Low: Monitor cybercrime forums and dark web sources for mentions of your organization’s data or credentials. Establish an incident response plan for rapid containment and remediation in the event of a confirmed breach.
Indicators of Compromise
The following indicators are provided as a point-in-time reference and should be validated in your environment before enforcement. These IOCs are derived directly from the primary source and are defanged for safe publication.
Type | Indicator | Reported (date) | Source
|
Domain | onmicrosoft[.]com | 2026-08-16 | https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/ |
Domain | www[.]hudsonrock[.]com | 2026-08-16 | https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/ |
Domain | www[.]infostealers[.]com | 2026-08-16 | https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/ |
URL | hxxps://www[.]hudsonrock[.]com/blog/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others | 2026-08-16 | https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/ |
URL | hxxps://www[.]infostealers[.]com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/ | 2026-08-16 | https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/ |
References
https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/ https://www.hudsonrock.com/blog/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others
About Rescana
Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor risks associated with external vendors and partners. Our platform enables continuous monitoring of supply chain exposures, credential leaks, and third-party vulnerabilities, supporting proactive risk mitigation and incident response.
For further questions or to discuss this advisory, please contact us at info@rescana.com.


