
The Data Governance Crisis No One Has Fully Solved
Enterprise IT estates now often have more than 100 times as many machine identities as humans.


You may have seen the news reports already, almost all of them repeating very similar text to make very similar claims.
Simply put, media feeds say that a data-stealing cybercriminal going by The Hatman has been breaking into lots of big companies hosted on Microsoft Azure by using stolen credentials (phished, perhaps, or guessed, or bought up from other cybercrooks – no one is quite sure), and has stolen huge amounts of sensitive information (or exfiltrated it, in the spy-versus-spy jargon favored by the cybsecurity industry).
Various outlets have made claims that start out with what sounds like certainty, but most if not all have qualified their stories by injecting words such as reportedly, allegedly, and apparently:
“A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials.”
“A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.”
“A cybercriminal is touting on underground marketplaces massive quantities of employee information apparently exfiltrated from Microsoft Azure environments maintained by major corporations.”
“A sprawling Azure data exfiltration campaign is unfolding across the dark web, with a threat actor systematically selling internal employee directories allegedly stolen from some of the world’s largest corporations.”
So far, the companies that Hatman claims to have plundered include: takeway giant McDonald’s; global telecomms operator Vodafone; and Indian IT outsourcing juggernauts Tata Consultancy Services and HCL Technologies.
Employee data from McDonald’s, Hatman insists, includes personally identifiable information (PII) such as employee IDs, phone numbers, home addresses, and more.
We’re assuming that if the stolen PII included super-sensitive data such as SSNs (social security numbers), driving license scans, bank and tax records, and the like, Hatman would have bragged about that.
However, like everyone else who is hedging their bets in telling this story, we’re bound to say that this is merely an assumption.
What really was stolen, and how dangerous would it be if Hatman sold it on, or dumped it out of spite if no one stepped up to pay for it?
Working out what really was stolen after a data breach is hard enough for attack victims; proving what wasn’t taken can be as good as impossible, especially if the attackers had sufficient access rights that they were able to tamper with access logs and could effectively “rewrite history” after the event.
Tata Consultancy Services (TCS) opened its account by writing to the National Stock Exchange of India to say:
[We have] investigated the matter and [have] not found any credible evidence of a breach of TCS systems or customer environments. The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.
The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. [We have] had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and [we continue] to monitor the environment closely.
That’s an interesting choice of words, with Tata effectively admitting that some of its data has indeed been stolen, albeit not recently, and implying that it’s unimportant because it’s just “basic employee information” and “more than four years old.”
That will be cold comfort, no doubt, to any employees who have worked at Tata for more than four years, especially if they still live at the same address, have the same phone number, and so on.
Data breach news followers will likely recall that the infamous Jaguar Land Rover cyberattack in 2025, which is now said by the Bank of England to have affected the GDP of the UK, and which necessitated a $2 billion government loan to protect Tata-owned JLR and its suppliers, happened in spite of a much-vaunted five-year contract with TCS, signed in 2023 for a range of IT services, including cybersecurity.
If you’re a LinkedIn user and you’re not yet following @SolCyber, do so now to keep up with the delightfully useful Amos The Armadillo’s Almanac series. SolCyber’s lovable mascot Amos provides regular, amusing, and easy-to-digest explanations of cybersecurity jargon, from MiTMs and IDSes to DDoSes and RCEs.
Even if you know all the jargon yourself, Amos will help you explain it to colleagues, friends, and family in an unpretentious, unintimidating way.
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!
Featured image of steampunk hat by Johnny Briggs via Unsplash.

Enterprise IT estates now often have more than 100 times as many machine identities as humans.

Cyberattacks continue to increase. In 2020, 77% of IT leaders reported an uptick in how often cyberattacks were happening, according to Cybersecurity Magazine. Despite the rise in attacks, companies had to cut headcounts, leading to an additional burden on IT teams. In 2021, 83% of IT leaders were considering outsourcing their security needs, likely because they couldn’t properly manage so many threats. Although outsourcing security significantly reduces the workload on internal teams, choosing the right outsourced solution can be difficult, […]

Seen posts implying Let’s Encrypt got hacked? They were wrong!

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






