
A newly reported cybercrime campaign is providing another reminder that attackers don’t always need to exploit a sophisticated software vulnerability to create serious risk. Sometimes, they simply need the right information about the right employees.
A threat actor operating under the name “TheHatman” is reportedly offering millions of employee records allegedly obtained from Microsoft Azure and Entra environments belonging to major global organizations. Companies named in the listings include McDonald’s, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. Researchers say the advertised datasets collectively represent millions of records.
The exposed information is especially concerning because it reportedly goes far beyond a simple list of email addresses. Samples have included employee names, corporate email addresses, phone numbers, job titles, departments, manager relationships, group memberships, service accounts, and other directory information. Some datasets reportedly identify highly privileged accounts, including Global Administrators.
While the exact circumstances surrounding each dataset remain under investigation—and some companies have disputed aspects of the claims—the larger security lesson is clear.
This type of information can become a roadmap for social engineering.
Imagine receiving an email that appears to come from someone in your IT department. The sender knows your name, title, department, manager, and company email address. They may even know which employees have elevated administrative privileges.
The request isn’t generic. It is tailored specifically to you.
That is what makes spear phishing so dangerous.
With accurate organizational information, criminals can impersonate executives, IT administrators, HR personnel, vendors, or coworkers. They can construct believable stories designed to convince employees to disclose credentials, approve an MFA request, open a malicious attachment, transfer information, or provide access to corporate systems.
SecurityWeek notes that information about reporting structures and privileged accounts can enable convincing spear-phishing, business email compromise, and targeted privilege-escalation attacks.
Technology remains essential to cybersecurity, but technical controls alone cannot eliminate social engineering risk. Attackers deliberately target people because a convincing message can sometimes bypass layers of expensive security technology.
That makes recurring security awareness training essential.
Employees need to regularly practice recognizing suspicious requests, phishing emails, impersonation attempts, credential-harvesting techniques, MFA fatigue attacks, and other evolving social engineering tactics. Training once during onboarding or once a year simply isn’t enough. Attack techniques change, employees forget, and criminals continuously improve their methods.
Organizations should build a culture in which employees instinctively stop, question, verify, and report suspicious communications.
That’s where uRISQ can help.
uRISQ makes it easy to provide employees with recurring cybersecurity and privacy training on critical topics such as phishing and social engineering. And with our automated training administration engine, organizations can simplify the work behind the program—from assigning training to keeping employees on track—without creating another administrative burden for security and compliance teams.
TheHatman campaign demonstrates why employee information can be valuable to attackers. When cybercriminals have a roadmap to your people, make sure your people are prepared for what may be coming next.
With uRISQ, building that human layer of defense can be simple, consistent, and continuous.
18
Aug| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |

