I
Agentic Intelligence · Infomly

9 Fortune 500 companies just had 3.6 million employee records stolen. No vulnerability was exploited.

AI-Assisted Content — Produced with AI assistance and human editorial review. Learn more
A threat actor called "TheHatman" just exfiltrated 3.64 million employee records from 9 Fortune 500 companies through Microsoft Azure.

McDonald's. Vodafone. TCS. HCL. IHG. Kyndryl. Gap. Hexaware. Wyndham.

No zero-day. No exploit chain. Just compromised credentials from infostealer logs.

The data includes employee names, corporate emails, job titles, phone numbers, service accounts, and global admin names. Hudson Rock confirmed the dumps match Azure directory export structures across all 9 tenants.

Here is what should terrify you:

The dumps contain service account names and global admin identities. That is a roadmap for the next attack. Spear-phishing. Business email compromise. Privilege escalation. Every company on this list is now a target for follow-on operations.

And the attacker didn't need to break anything. They used password spray and MFA fatigue against Azure Entra ID. Stolen credentials from infostealer malware did the rest.

TCS says the data is 4 years old. Gap says it's non-sensitive. Both deny breach of corporate systems.

That doesn't matter. The employee directory structure alone is enough to map your organization, identify high-value targets, and craft convincing phishing campaigns that bypass every control you have.

Audit your Entra ID tenant today. Rotate service account credentials. Review which accounts have global admin privileges. The next attack isn't coming through your firewall. It's walking through your front door with a valid password.

SOURCE: https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
VERIFIED: BleepingComputer (August 17, 2026), SecurityWeek (August 17, 2026), Hudson Rock (August 16, 2026)
SIGNAL: Credential-based attacks against Azure/Entra ID are now targeting Fortune 500 directories at scale. Service account exposure creates follow-on attack surface that most enterprises haven't audited.
💬 Consultation · Got questions? Talk to an expert →
Enterprise AI Impact — filtered for signal, not noise The AI briefing CTOs read before their morning meeting 3 minutes. Zero fluff. Only what moves the needle. $5/mo — your cheapest competitive edge
Subscribe — $5/mo

0 Comments

No comments yet. Be the first.