No exploit. No malware. Just valid credentials and 3.6 million employee records walking out of Azure.

A threat actor calling himself "TheHatman" is selling internal directory data allegedly pulled from the Azure/Entra tenants of Fortune 500 organizations — McDonald's (~1.7M records), TCS (~800K), Vodafone (~425K), HCL (~250K), plus Kyndryl, IHG, Gap, Hexaware and Wyndham on the claimed victim list.

WHAT ACTUALLY HAPPENED

The records include names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts and other tenant account attributes.

Hudson Rock analyzed the dumps and confirmed they contain foundational corporate directory attributes with a coherent structure, including active domains and tenant-specific .onmicrosoft.com naming. The actor says the data was exfiltrated using leaked credentials. Candidate routes: stolen credentials, phishing, voice phishing, infostealer malware, or a third-party application holding broad delegated access to corporate data.

WHY AN ORG CHART IS AN ATTACK TOOL

Directory data gets classified as low sensitivity because it contains no passwords and no financials. That classification is a mistake.

A full corporate directory tells an attacker who reports to whom, which accounts are service accounts, what the internal email format is, and which job titles sit near money or infrastructure. That is the raw material for targeted phishing, for help-desk social engineering ("this is the CFO's assistant"), and for voice-phishing campaigns that sound credible because they are. This breach is not the incident — it is the pre-work for the next one.

WHAT TO DO NOW

AUDIT ENTRA APP CONSENTS AND SERVICE PRINCIPALS — third-party apps with Directory.Read.All are a quiet, credential-free path to exactly this data; revoke what nobody can justify.

ALERT ON BULK DIRECTORY ENUMERATION — large Graph API reads of user objects from an unusual IP or a rarely used service principal should page someone.

HARDEN THE HELP DESK AGAINST IDENTITY-RICH CALLERS — an attacker who knows an employee's ID, manager and title will pass most verbal verification scripts, so require an out-of-band factor for resets.

ASSUME YOUR DIRECTORY IS ALREADY PUBLIC — build controls that survive an adversary knowing your entire org chart, because that is the operating assumption now.

The breach that leaks no passwords is often the one that makes the next intrusion trivial.

Is your employee directory classified as public data — or defended like it is?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.