TheHatman is a cybercriminal persona associated with the sale of alleged internal employee-directory datasets from major multinational enterprises on cybercrime forums. Beginning in July 2026, the actor advertised records purportedly collected from Microsoft Azure and Entra tenants belonging to organizations in retail, hospitality, telecommunications, and IT services, including McDonald’s, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels. The actor claimed to have accessed the datasets with compromised credentials. Samples were assessed as likely authentic corporate-directory exports based on their corporate email patterns and Azure directory-consistent structures, although the initial-access mechanism and full scope of the alleged compromises remain unconfirmed. The advertised data included employee identity and contact information, organizational reporting structures, group memberships, service accounts, and, in some cases, Global Administrator account information. This information can enable targeted spear-phishing, social engineering, business email compromise, and follow-on privilege-escalation activity. TheHatman is also known as The Hatman and the_hatman.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Selling allegedly authentic Azure/Entra corporate directory dumps exfiltrated from major retail and hospitality organizations using compromised credentials, with exposure of identity data, group memberships, and privileged account records.
Advertising and dumping large volumes of allegedly exfiltrated employee directory data from multiple companies, claiming the data was downloaded from Azure tenants using compromised credentials.
Forum seller offering an alleged dump of 1.7 million McDonald's employee records, claimed to have been stolen from the company's Azure tenant using compromised credentials.
Conducting a mass corporate-directory data-exfiltration and sale operation affecting global retail and hospitality organizations. The actor allegedly uses compromised credentials to access Azure/Entra tenants and exports employee identity data, organizational structures, group memberships, service-account information, and privileged-account names. The claimed access vector includes password spraying and MFA-fatigue attacks; the reporting also assesses infostealer-derived credentials and session tokens as a likely initial-access source.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.