CyberSecurity SEE

Azure Breach Campaign Targets McDonald’s and Vodafone as Victims

Azure Breach Campaign Targets McDonald’s and Vodafone as Victims

Cybercrime,
Fraud Management & Cybercrime,
Incident & Breach Response

Darknet Forums List Employee and Service Records Allegedly Stolen From Major Firms

Azure Breach Campaign Targets McDonald’s and Vodafone as Victims
Image: Shutterstock/ISMG

In a striking revelation, a cybercriminal has surfaced in underground marketplaces boasting of a vast cache of employee information purportedly exfiltrated from Microsoft Azure environments maintained by prominent corporations. The nature of this data breach highlights the ongoing and escalating threat posed by cybercrime as businesses increasingly rely on cloud technologies.

The apparent victims of this breach extend across various sectors, including retail, logistical services, consultancy, hospitality, and telecommunications. Notable names mentioned include McDonald’s, Tata Consultancy Services, Vodafone, and HCL Technologies. Tata Consultancy Services reported that the data being offered for sale is likely to be at least four years old, raising questions about its relevance and how it may still pose a risk.

The seller, identified online as “TheHatman,” claims to offer over 1.7 million records from McDonald’s alone. This trove supposedly includes sensitive employee information such as full names, employee ID numbers, email addresses, job titles, phone numbers, as well as home addresses. Intriguingly, some listings—even those for reputable firms like Kyndryl—specifically mention containing information related to “global admins.”

Security experts indicate that this type of data is invaluable for cybercriminals who can employ it for social engineering attacks targeting employees with privileged access to sensitive systems. The concerns surrounding the exposure of service accounts and names of global admins are paramount, as they provide cybercriminals with a direct roadmap for further attacks, including social engineering, spear-phishing, or escalating privileges within the organizations involved.

Hudson Rock, a threat intelligence firm adept at tracking information-stealing malware, emphasized the gravity of the situation in a Sunday report. They noted that the exposure of critical data could potentially facilitate targeted attacks by initial access brokers or more sophisticated ransomware groups. Such alarming scenarios outline the reality of modern cybersecurity challenges, where each breach exposes organizations to further threats.

Numerous security professionals who examined samples of the compromised data confirmed its authenticity. Alarmingly, certain entries included phone numbers, a detail that raises red flags given how extortion groups like Scattered Spider have previously leveraged such information. This could enable adversaries to manipulate help desk employees into unwittingly granting access to corporate systems.

Victim Listings

The listings for sale by TheHatman include information reportedly stolen from various firms:

  • McDonald’s: 1.7 million records;
  • Tata Consultancy Services (Mumbai): 800,000 records;
  • Vodafone (United Kingdom): 425,000 records;
  • HCL Technologies (India): 250,000 records;
  • Kyndryl (New York): 170,000 records;
  • InterContinental Hotels (operating over 6,300 branches worldwide): 185,000 records;
  • Gap (San Francisco-based retailer): 80,000 records;
  • Hexaware Technologies (India): 20,000 records;
  • Wyndham (a global hotel franchiser): 9,000 records.

All the compromised data reportedly originated from Microsoft Entra portals of the respective victim companies. One of TheHatman’s advertisements explicitly stated, “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials.” This claims speaks volumes about the precarious state of data security in corporate environments.

An Azure tenant pertains to a unique instance of Microsoft Entra ID designated to a business when it enrolls in a Microsoft cloud service. This infrastructure handles user identities and manages user groups to register for access to applications. Given the significance of this data, it becomes clear that any deficiency in security protocols could lead to substantial information exposure.

TheHatman began listing victims of this hacking campaign starting from August 1, with additional entries emerging in the weeks that followed. Many of these listings are reportedly cross-posted across multiple darknet forums, including DarkForum, PwnForums, and BreachForums, all notorious for listing stolen data.

Threat intelligence firm Kela highlighted that DarkForum is a prominent Russian-speaking platform dedicated to leaking or selling databases, cracked accounts, source codes, and cracked tools. Meanwhile, PwnForums and BreachForums serve as alternative venues for similar transactions, highlighting the pervasive nature of illicit data trading in the digital landscape.

On August 9, listings for Tata Consultancy Services surfaced, and the company informed investors the next day that the mentioned data seemed to be over four years old and chiefly consisted of basic employee information. TCS asserted that there were no indicators suggesting that their systems had been compromised.

Despite these claims, the attacker suggested that methods such as password spraying and multifactor authentication fatigue were used to facilitate the breach. TCS indicated that robust safeguards have been operational against such tactics for more than two years, with ongoing monitoring of their systems yielding no current vulnerabilities.

Unclear Attack Vector

The precise methodology behind the data theft remains uncertain; however, observers note that the scale and rapidity of these data dumps imply a systematic, automated operation once initial access has been secured. One possible scenario is that the attacker, or an initial access broker, targeted employee credentials through phishing attacks or voice phishing tactics.

Modern “phishing-as-a-service” tools can streamline the real-time capture of multifactor credentials or session tokens through adversarial techniques. Infostealer malware could also have played a role, as it can capture these sensitive details, providing further facilitation for the malicious actors involved.

Evaluating the attack’s initial vector reveals a chilling reality: how easily accessible data is to unauthorized users, irrespective of their access levels. Individuals with low-level credentials might inadvertently grant adversaries significant visibility within corporate ecosystems, illustrating vulnerabilities often overlooked in security protocols.

As data security continues to be a pressing concern, firms must reassess their cybersecurity frameworks to ensure robust defenses against the evolving landscape of cyber threats. The gravity of this situation emphasizes the need for heightened vigilance and comprehensive risk management strategies in the digital era.

Source link

Exit mobile version