TCS, HCL, Hexaware named in global Azure directory data leak linked to infostealers
Threat actor claims to have extracted employee directories from nine enterprise Azure/Entra environments using compromised credentials.
Tata Consultancy Services (TCS), HCL Technologies and Hexaware Technologies are among nine global enterprises whose internal employee directories a threat actor claims to have extracted from Microsoft Azure/Entra environments using compromised credentials.
The threat actor, operating under the alias “TheHatman”, is offering the data on cybercrime forums, according to a report published by cybersecurity firm Hudson Rock on August 16.
The other organisations named are McDonald’s, Vodafone, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., and Wyndham Hotels.
The threat actor claims the directories were downloaded directly from the organisations’ Azure/Entra tenants. Hudson Rock says the samples it reviewed appear consistent with genuine corporate directory exports, based on corporate email addresses and field structures found in the data.
None of the named companies have publicly confirmed the alleged exposure. The available information also does not establish how the attacker gains access to each organisation’s environment.
Scale of the alleged exposure
The threat actor lists over 3.6 million records across the nine organisations.
McDonald’s has the largest dataset at more than 1.7 million records, followed by TCS with over 800,000 and Vodafone with about 425,000.
(Figures as alleged by the threat actor and reported by Hudson Rock; not independently confirmed by the affected companies.)
The alleged datasets contain employee names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles and department information.
They also reportedly include manager and reporting relationships, group memberships, service accounts and information identifying Global Administrator accounts.
The information gives attackers visibility into an organisation’s employee structure and privileged identities, which can support targeted attacks against specific employees and administrators.
TCS has said the employee data referenced in a recent threat-intelligence alert "appears to be" more than four years old, stopping short of confirming its exact age or origin.
The company made the statement in a filing with the BSE, after receiving threat intelligence alerts about the possible exposure of employee information.
TCS said it has not found any credible evidence of a breach of its systems or customer environments. It added that the information referenced in the alerts is limited to basic employee details, and that there is no indication customer data, customer systems or its own operational systems have been impacted.
Infostealers emerge as possible entry point
The threat actor provides only one explanation for how the data is obtained, saying compromised credentials are used to access the affected environments.
Hudson Rock says its threat-intelligence platform identifies compromised Azure credentials linked to Infostealer infections at several of the named organisations, including TCS, HCL Technologies, Gap and Kyndryl.
Infostealers are malware that can collect credentials, browser cookies and other authentication information from infected devices.
The findings point to stolen identity information as a possible route into the affected environments. However, Hudson Rock does not establish that Infostealer infections directly enable the directory extraction at every organisation.
Other possible entry points include phishing, weak or inconsistently enforced multi-factor authentication, stolen session information or third-party applications with excessive access to Microsoft environments.
The available evidence also does not indicate a vulnerability in Microsoft Azure itself.
Hudson Rock's assessment points towards compromised credentials rather than a platform-level Azure flaw. The researchers also note that compromised Azure credentials linked to Infostealer infections are identified across several of the affected organisations.
What the exposure means for India's IT channel
For Indian MSPs and system integrators managing Microsoft 365 and Entra environments, the incident highlights the connection between endpoint security and cloud identity security.
An employee device infected with an Infostealer can expose credentials or session information used to access enterprise cloud services. This means a compromise that starts on one endpoint can create a wider identity risk for the customer environment.
Partners managing Microsoft environments therefore need visibility across both endpoints and cloud identities.
This includes monitoring compromised credentials, reviewing privileged accounts and identifying unusual access to cloud environments.
The exposure of Global Administrator and service account information also increases the value of the stolen directory data. Attackers can use these details to identify privileged users and build targeted phishing or Business Email Compromise campaigns around known employees and reporting relationships.
For security partners, the incident also highlights opportunities around identity monitoring, compromised-credential detection, privileged access management and managed security services.
What remains unconfirmed
The threat actor’s claims remain the starting point for the reported exposure. Hudson Rock says the samples it reviews appear legitimate, but the affected companies have not confirmed the alleged breach.
The evidence also does not establish the complete attack chain or confirm that the same method is used against every organisation.
The current information therefore points to a possible campaign involving compromised corporate identities and Infostealer-linked credentials, rather than a confirmed Azure platform breach.