A threat actor using the alias "TheHatman" is advertising and selling data allegedly stolen from the Azure and Entra tenants of at least nine large enterprises, including McDonald’s, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. The exposed datasets reportedly contain millions of records and appear to be legitimate internal employee directory exports, including employee identities, contact details, job titles, manager relationships, organizational structure, group memberships, service accounts, and in some cases Global Administrator or other privileged account listings.
Researchers said the data samples appear credible and follow a consistent Azure directory export-like structure, increasing concern that the information was exfiltrated through compromised credentials rather than any underlying Azure platform flaw. Reporting points to a targeted credential-theft operation, with infostealer infections, phishing, weak MFA enforcement, or abuse of third-party API permissions cited as likely access paths; investigators also linked compromised Azure credentials tied to several affected firms. The exposure creates immediate risk of spear-phishing, business email compromise, social engineering, and privilege escalation against the impacted organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The threat actor 'TheHatman' began advertising alleged employee databases stolen from major companies' Azure or Entra tenants, claiming access via compromised credentials. The campaign ultimately advertised about 3.64 million records across multiple companies and included sample datasets for buyers.
Tata Consultancy Services said it received threat-intelligence alerts about possible exposure of employee information but found no credible evidence of a breach of its systems or customer environments. TCS said the referenced data appears to be more than four years old, limited to basic employee information, and that customer, operational, and customer-system data were not impacted.
Hudson Rock reported finding compromised Azure credentials tied to infostealer infections associated with most of the affected companies, including specific links to Tata Consultancy Services, Gap, HCL Technologies, and Kyndryl. The researchers assessed that the victim pattern pointed to targeted credential theft rather than an underlying Azure platform vulnerability.
Hudson Rock said sample datasets appeared legitimate and matched the structure of Azure directory exports, with fields including employee identities, contact details, organizational hierarchy, service accounts, and in some cases privileged account listings. Researchers warned that the exposed information could support spear-phishing, business email compromise, and privilege escalation.
A threat actor using the alias 'TheHatman' offered for sale internal employee directory data allegedly stolen from at least nine large organizations' Azure and Entra tenants, including McDonald’s, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware, and Wyndham Hotels. The actor claimed the data was obtained using compromised credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcetheregister.com
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcecybersecuritynews.com
Open sourceinfostealers.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.