Hacker claims millions of records stolen from corporate Azure tenants
Hudson Rock says a hacker group called “TheHatman” posted millions of employee records allegedly taken from Azure tenants of firms including McDonald’s (about 1.7M records), TCS (~800k), Vodafone (~425k), and HCL (~250k). Researchers say samples look like Azure directory exports. TCS told the Bombay Stock Exchange it found no credible breach and said the data is over four years old.
How this was made

The 30-second read
Why it matters
The trading relevance is mainly cyber-risk headline exposure. The article provides one concrete issuer response (TCS) denying a credible breach and characterizing the data as older and limited to basic employee details. For other named firms, the article does not include confirmation or company statements, so the incremental decision value is limited until follow-on verification emerges.
Market read
Cyber-incident claims tied to Azure tenant exports can move sentiment, but without confirmed breach scope for most firms, the actionable trading signal is modest. TCS’s denial is a key offset.
What to watch
Even if the intrusion vector is unconfirmed, the mention of global admin names and service accounts could drive disproportionate follow-on phishing risk, which may matter more than direct customer-system compromise for near-term risk pricing.
Background
Hudson Rock reports that a threat actor (“TheHatman”) posted large internal employee directory dumps allegedly taken from multiple Fortune 500 companies’ Azure tenants; researchers sampled data and found fields consistent with Azure directory exports.
Ticker impact
Vodafone is named as an alleged victim, with the attacker claiming roughly 425,000 employee records taken from its Azure environments.
Moderate downside risk to sentiment if further evidence confirms unauthorized access or expands to customer-impacting systems.
The article is based on threat-forum postings and third-party analysis; it does not provide Vodafone’s response or confirmed breach findings.
Kyndryl is listed among alleged victims, with the attacker claiming employee-directory dumps from its Azure tenants.
Low to moderate near-term impact, contingent on whether Kyndryl confirms breach and the scope of affected systems.
No company statement or evidence of confirmed compromise is included for Kyndryl in the article.
InterContinental Hotels Group (IHG) is named as an alleged victim, with the attacker claiming employee-directory data from Azure tenants.
Low immediate impact unless subsequent reporting confirms breach scope or operational disruption.
This is primarily a threat-actor claim with no corroborating company statement in the provided text.
Wyndham Hotels is included among alleged victims, with the attacker claiming employee records from Azure tenants.
Low immediate impact unless Wyndham confirms unauthorized access or reports incident costs.
No Wyndham response or confirmed breach details are provided in the text.
Market effects
Highlights ongoing identity and Azure tenant exposure risk, potentially increasing investor focus on MFA, admin account hardening, and third-party integration privilege controls across large enterprises.
Primarily impacts global large-cap sentiment, with TCS’s response tied to India’s BSE disclosure process.
Cyber-incident headlines can spill over to cloud security vendors and enterprise IT spend expectations, though this article lacks confirmed breach scope beyond TCS’s denial.
Counterpoint
Because the article includes TCS’s statement that it found no credible evidence of a breach and suggests the data is over four years old, the market may treat most claims as unverified threat-forum noise rather than a fresh, monetizable incident.
Key entities
- threat_actorTheHatman
Threat actor claiming millions of employee records were exfiltrated from Azure tenants and posted them on cybercrime forums.
- researcherHudson Rock
Security firm analyzing leaked samples and assessing likelihood of authenticity while noting intrusion vector remains unknown.
- companyTCS
One named victim that filed a BSE statement saying it found no credible evidence of a breach and that referenced data appears older and limited.


