When a threat actor lists Vodafone, McDonald’s, TCS, HCL Technologies, IHG, Kyndryl, Gap and Wyndham as victims in the same breach post, the instinct is to check whether Azure itself has a hole in it. It does not, and that is the part worth sitting with.
Millions of records, one common cause
A threat actor operating under the handle TheHatman has been advertising data allegedly exfiltrated directly from the Azure and Entra tenants of multiple Fortune 500 companies. The McDonald’s dataset is the largest at over 1.7 million records, followed by TCS at 800,000, Vodafone at 425,000, HCL Technologies at 250,000 and IHG at 185,000. The exposed data includes employee names, corporate email addresses, phone numbers, employee IDs, job titles, manager relationships, group memberships and, in some cases, service account and privileged account details, exactly the kind of directory data an attacker needs to move laterally inside a corporate network once they have a foothold.
The cause is not a Microsoft flaw
Researchers at Hudson Rock traced the access back to compromised Azure and Entra credentials tied to infostealer malware infections, machines at TCS, Gap and HCL Technologies among those identified. No confirmed Azure zero-day is involved. An infostealer sits on an employee’s endpoint, harvests browser-saved passwords, session cookies and authentication tokens, and ships them to whoever is running the malware. If that endpoint has valid Azure or Entra credentials cached anywhere reachable, the attacker walks into the tenant using a login that looks completely legitimate to every access log.
Why this keeps happening to well-resourced companies
These are not under-resourced organisations. Vodafone, McDonald’s and TCS run mature security operations by any standard, and it did not stop this. That is the pattern worth internalising: the security perimeter that matters most for cloud identity is not the cloud provider’s infrastructure, it is every employee endpoint that has ever authenticated into that tenant. Multi-factor authentication that does not survive a stolen session token, endpoint protection that misses a new infostealer variant, or a credential rotation policy measured in months rather than days all leave the same door open that let TheHatman in.
The practical fixes are not exotic
Conditional access policies that flag impossible travel and unfamiliar devices, session token lifetimes short enough that a stolen cookie goes stale before it is useful, endpoint detection tuned specifically for infostealer behaviour rather than generic malware signatures, and routine audits of which service accounts and privileged identities exist in a tenant and whether they still need to. None of that requires replacing Azure or Entra. It requires treating every endpoint with a cached credential as part of the identity perimeter, because that is where this campaign actually got in.
If your organisation runs its identity infrastructure on Azure AD or Entra ID and you are not certain your endpoint protection would catch an infostealer before it harvests a session token, contact Excello Digital. We help European businesses close the gap between cloud identity controls and the endpoints that hold the keys to them.
