A threat actor using the alias "TheHatman" is advertising and selling data allegedly stolen from the Azure and Entra tenants of at least nine large enterprises, including McDonald’s, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. The exposed datasets reportedly contain millions of records and appear to be legitimate internal employee directory exports, including employee identities, contact details, job titles, manager relationships, organizational structure, group memberships, service accounts, and in some cases Global Administrator or other privileged account listings.
Researchers said the data samples appear credible and follow a consistent Azure directory export-like structure, increasing concern that the information was exfiltrated through compromised credentials rather than any underlying Azure platform flaw. Reporting points to a targeted credential-theft operation, with infostealer infections, phishing, weak MFA enforcement, or abuse of third-party API permissions cited as likely access paths; investigators also linked compromised Azure credentials tied to several affected firms. The exposure creates immediate risk of spear-phishing, business email compromise, social engineering, and privilege escalation against the impacted organizations.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
The threat actor 'TheHatman' began advertising alleged employee databases stolen from major companies' Azure or Entra tenants, claiming access via compromised credentials. The campaign ultimately advertised about 3.64 million records across multiple companies and included sample datasets for buyers.
Gap Inc. said its preliminary investigation found no evidence of a breach related to TheHatman's advertised Azure/Entra data. The company described the referenced information as limited in scope, non-sensitive, and several years old.
Tata Consultancy Services said it received threat-intelligence alerts about possible exposure of employee information but found no credible evidence of a breach of its systems or customer environments. TCS said the referenced data appears to be more than four years old, limited to basic employee information, and that customer, operational, and customer-system data were not impacted.
Hudson Rock reported finding compromised Azure credentials tied to infostealer infections associated with most of the affected companies, including specific links to Tata Consultancy Services, Gap, HCL Technologies, and Kyndryl. The researchers assessed that the victim pattern pointed to targeted credential theft rather than an underlying Azure platform vulnerability.
Hudson Rock said sample datasets appeared legitimate and matched the structure of Azure directory exports, with fields including employee identities, contact details, organizational hierarchy, service accounts, and in some cases privileged account listings. Researchers warned that the exposed information could support spear-phishing, business email compromise, and privilege escalation.
A threat actor using the alias 'TheHatman' offered for sale internal employee directory data allegedly stolen from at least nine large organizations' Azure and Entra tenants, including McDonald’s, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware, and Wyndham Hotels. The actor claimed the data was obtained using compromised credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
16 references tracked. Mallory keeps watching after this page renders.
rhisac.org
Open sourcesecuritymagazine.com
Open sourceteiss.co.uk
Open sourcescworld.com
Open sourcesecurityweek.com
Open sourcecybersecuritynews.com
Open sourcehudsonrock.com
Open sourceinfostealers.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.