data leak
TheHatman Sells 3.6 Million Azure Employee Records From Fortune 500 Companies
> By Clara | Aug 18, 2026 | 6 min read
Since July 31, a underground cybercrime forum has been flooded with listings from a user going by the alias “TheHatman,” offering internal employee databases from a number of major global companies. The total data on offer amounts to 3.64 million records, and according to the listings, all of it was downloaded directly from victims’ Microsoft Azure tenants using compromised credentials.

What Happened
The largest and most recent listing appeared over the weekend, containing more than 1.7 million employee records from McDonald’s Corporation. In the sales description, TheHatman described the file as an internal employee dump pulled directly from McDonald’s Azure tenant using compromised credentials.
Beyond McDonald’s, nine Fortune 500-scale organizations were named across the same series of postings, spanning technology services, hospitality, telecommunications, retail, and logistics. The record counts circulating on the forum break down as follows:
- McDonald’s Corporation — more than 1.7 million records
- Tata Consultancy Services (TCS) — approximately 800,000 records
- Vodafone — approximately 425,000 records
- HCL Technologies — approximately 250,000 records
- InterContinental Hotels Group (IHG) — approximately 185,000 records
- Gap Inc. — approximately 80,000 records
- Hexaware Technologies — approximately 20,000 records
- Wyndham Hotels — approximately 9,000 records
Data Exposed
According to the descriptions attached to each listing, the data for sale includes full names, employee IDs, corporate email addresses (including active domains and tenant-specific .onmicrosoft.com structures), phone numbers, physical addresses, job titles, departments, manager names, and direct-report listings. More concerning, several datasets also contain user group membership details, service accounts, and high-privilege account records, including Global Administrator listings.
This combination of data gives other cybercriminals a fairly complete roadmap for building social engineering attacks, spear-phishing campaigns, or targeted privilege-escalation attempts against these organizations.
Third-Party Analysis
Cybercrime intelligence firm Hudson Rock reviewed sample datasets that TheHatman shared with prospective buyers as proof of authenticity. Based on their analysis, the field structures and corporate email domains present in the samples closely match standard Azure directory export formats, leading Hudson Rock’s research team to assess the data as likely authentic, even though the exact access and exfiltration method has not been fully established.
Hudson Rock also noted that the pattern of victims — all Fortune 500-scale — suggests the campaign most likely stems from exploitation of stolen credentials via infostealer malware infections on employee devices, rather than a systemic vulnerability in the Azure platform itself. If a broad platform-level flaw were involved, the researchers noted, the attack pattern would likely extend to smaller organizations as well, not just corporate giants.
In separate findings, Hudson Rock identified compromised Azure Active Directory credentials belonging to a TCS employee, traced to an infected machine in India; a compromised Gap Inc. corporate account exposed through an infostealer infection; and HCL Technologies employee credentials showing signs of password reuse. In Kyndryl’s case, researchers found a single heavily compromised machine holding dozens of corporate credentials along with hundreds of sensitive cookies, including direct access to a Kyndryl Azure Active Directory account.
Attack Vector
TheHatman has not detailed the exact intrusion method beyond citing “compromised credentials.” Researchers point to several plausible vectors, including infostealer malware harvesting credentials and session tokens stored in employee browsers, successful phishing campaigns reaching administrative accounts, inconsistent or weak multi-factor authentication enforcement across certain tenants, and possible abuse of third-party integrations with excessive read access across cloud environments.
In the listing specifically targeting TCS, TheHatman referenced the use of password spraying — attempting a limited set of common passwords across a large number of accounts — combined with MFA fatigue attacks, which flood a target with repeated authentication requests until the victim unknowingly approves one.
Response From Affected Companies
TCS was among the first companies to respond officially. In a notification to the National Stock Exchange of India, TCS stated that it conducted an internal investigation and found no credible evidence of a breach of its systems or customer environments. The company added that the data in circulation appears to be at least four years old and contains only basic employee information. Regarding the password spraying and MFA fatigue techniques referenced by TheHatman, TCS stated it has maintained strong safeguards against both techniques for more than two years, and its review confirmed its defenses remain effective.
Echoing TCS, a Gap Inc. spokesperson told BleepingComputer that the company found no evidence of a breach on its infrastructure. Several other companies named in the listings — including McDonald’s, Vodafone, HCL Technologies, IHG, Kyndryl, Hexaware Technologies, and Wyndham Hotels — had not issued public statements detailing internal investigation results at the time this article was prepared.
Potential Impact
Even as several corporations dispute a breach of their core systems, the presence of data closely resembling an authentic Azure directory structure still carries real risk. A leaked employee directory — complete with names, titles, reporting structures, and corporate email addresses — provides an ideal foundation for convincing phishing emails, executive impersonation, and business email compromise schemes, as well as social engineering aimed at IT staff and senior administrators.
That risk is compounded by the presence of Global Administrator account records within several of the datasets. If identity information belonging to the individuals holding the highest privilege levels on a cloud tenant becomes public, downstream attackers could specifically target those individuals to gain deeper access into an organization’s cloud environment.
Threat Background
Campaigns like the one run by TheHatman are not new in the corporate cloud threat landscape. Over the past several years, infostealer malware families such as RedLine, Raccoon, and Lumma have become a primary source of large-scale corporate credential leaks, capable of harvesting browser-stored passwords, active session cookies, and authentication tokens from infected employee devices without the user’s knowledge. Credentials harvested this way are then traded on underground forums, becoming raw material for other actors seeking access to corporate Azure Active Directory or Microsoft Entra ID environments.
This pattern helps explain why Fortune 500-scale organizations — which typically maintain substantial security budgets and dedicated IT teams — can still end up as victims. The weak point is rarely the cloud infrastructure itself, but rather a single employee device that slips past endpoint protection, or a single account not yet fully covered by strict multi-factor authentication policy.
Recommended Mitigation Steps
For organizations running Microsoft Azure and Entra ID, this incident serves as a reminder of the importance of layered identity security. Commonly recommended steps from cloud security practitioners include enforcing phishing-resistant MFA methods such as FIDO2 or passkeys on all privileged accounts, actively monitoring for credential leaks through threat intelligence platforms, restricting Global Administrator access strictly to accounts that genuinely require it under a least-privilege model, and conducting regular audits of third-party integrations with read access to the tenant directory.
Employee security awareness training around infostealer malware risk — including the dangers of downloading pirated software or clicking suspicious links — also remains one of the most effective first lines of defense, given that most incidents of this kind originate from a single infection point on an end-user device rather than a systemic failure on the part of the cloud provider.
Conclusion
This incident reflects a recurring pattern in the threat landscape: not a sophisticated zero-day exploit, but the cumulative result of stolen credentials from infostealer malware infections and weak password hygiene at the end-user level. Nine Fortune 500-scale organizations now face public scrutiny over the incident, while some have already disputed a breach of their core systems. Further details on the actual initial access vector are still developing, and CyberAsia will update this report as additional confirmation emerges from the parties involved.
Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing TheHatman Sells 3.6 Million Azure Employee Records From Fortune 500 Companies is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for data leak threats, please refer to our Secure Drop or contact the research desk.