Over 3.5 Million Microsoft Azure Employee Records Allegedly Offered for Sale Online

More than 3.5 million employee records from the Microsoft Azure environments of several major companies are being offered for sale online, raising new worries about corporate cloud infrastructure and employee credentials. The claim is made in a report by BleepingComputer, and the databases in question involve brands as diverse as McDonald’s, Gap Inc., Vodafone, HCL Technologies, InterContinental Hotels Group (IHG) and Kyndryl.

Over 3.5 Million Azure Account Records Allegedly Hacked, Major Firms Named (Representative image) | Photo Credit: www.magnific.com
Over 3.5 Million Azure Account Records Allegedly Hacked, Major Firms Named (Representative image) | Photo Credit: www.magnific.com

The threat actor behind the claims is described as being “TheHatman” and has been selling huge amounts of employee information on the web to potential buyers. The actor said he has around 3.64 million records. But the databases have not been independently verified and companies should be wary of the claims.

The biggest database that was associated with the alleged breach is McDonald’s. It is said to contain more than 1.7 million employee records, according to the threat actor, and is the largest database advertised by it. It has employee names, identification numbers, email addresses, job titles, telephone numbers and postal addresses.

The database may also contain service accounts and other tenant-related information as well, if authentic, as the report said. That information could be useful to criminals in their phishing campaigns, impersonation attacks or other forms of social engineering. Employee information can be even more valuable if it is used to work out other publicly available data and is not directly associated with passwords or financial information.

Another large database belonging to Tata Consultancy Services, or TCS, is also reported to have more than 800,000 records. But TCS has denied that its systems or customer environments were hacked and denied any breach has ever happened, according to the company. TCS had also confirmed to the National Stock Exchange in a letter that it had received threat-intelligence alerts of employee information being leaked in the company’s systems and customer environments but found no evidence of a breach.

TCS said the information cited in the claims appeared to be more than four years old and was limited to basic employee information. The company also said there was no indication that customer data, customer systems or its operational systems had been affected. That’s significant because corporate information appearing in an alleged leaked database does not necessarily mean that the company’s current systems were hacked.

Gap Inc. has similarly said it found no evidence that its corporate systems had been compromised. As BleepingComputer writes, the company believes the information being advertised is limited in scope, non-sensitive and several years old.

The disconnect between the hacker's claims and the companies’ statements highlights one of the big challenges for data leak allegations. The information being sold online might come from older databases, previously exposed information, third-party systems or compromised credentials rather than a recent direct intrusion into a company’s core infrastructure.

According to the report, TheHatman has shared sample data with prospective buyers as part of the alleged sale. Those are samples that show that a database exists but do not in themselves suggest when or how the information was obtained. BleepingComputer also said it had no way to verify the databases' authenticity.

But it also demonstrates the increasing necessity of securing employees’ accounts in cloud-based corporate settings. Hackers can use compromised credentials to gain access to enterprise services if account data is not secured properly. Strong, unique passwords, multi-factor authentication and access controls are very effective at reducing the risk of stolen credentials.

Companies also need to routinely check employee accounts, remove unnecessary access and monitor unusual login activity. Security teams can use threat-intelligence monitoring to identify credentials or company information appearing in underground marketplaces and other suspicious online locations.

The incident is a reminder to employees to be cautious about unexpected emails, login requests and messages that request sensitive information. Attackers can use leaked names, job titles and corporate contact details to create convincing phishing messages that appear to come from colleagues, managers or legitimate service providers.

At present the databases reported are still under investigation and there is still uncertainty about the true scope and authenticity of the information provided. The reported exposure of millions of employee records is concerning, but it is not easy to relate any database to the true data breach. Companies and independent cybersecurity researchers will need to verify the source, age and accuracy of the information.

However, the episode shows how compromised credentials and old employee data can still pose security threats long after the information has been gathered. As companies adopt cloud platforms like Azure, having strong identity security, monitoring account activity as well as protecting employee information is very much at the forefront of cybersecurity today.