# TheHatman

> As of 2026-08-17, TheHatman is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning data breach. ATT&CK coverage spans 22 techniques across 10 tactics in 3 of 3 tracked threats. Most-observed techniques: T1621 (Multi-Factor Authentication Request Generation), T1069.003 (Cloud Groups), T1078.004 (Cloud Accounts).

- **Tracked threats:** 3
- **Categories:** DATA_BREACH
- **As of:** 2026-08-17

## ATT&CK techniques observed

22 techniques observed across 3 of 3 tracked threats. Tactics: Credential Access (6), Discovery (4), Initial Access (3), Collection (2), Lateral Movement (2), Reconnaissance (2).

- [T1621](https://intel.threadlinqs.com/technique/T1621) Multi-Factor Authentication Request Generation — Credential Access — observed in 3 of 3 tracked threats
- [T1069.003](https://intel.threadlinqs.com/technique/T1069.003) Cloud Groups — Discovery — observed in 2 of 3 tracked threats
- [T1078.004](https://intel.threadlinqs.com/technique/T1078.004) Cloud Accounts — Initial Access — observed in 2 of 3 tracked threats
- [T1087.004](https://intel.threadlinqs.com/technique/T1087.004) Cloud Account — Discovery — observed in 2 of 3 tracked threats
- [T1110.003](https://intel.threadlinqs.com/technique/T1110.003) Password Spraying — Credential Access — observed in 2 of 3 tracked threats
- [T1119](https://intel.threadlinqs.com/technique/T1119) Automated Collection — Collection — observed in 2 of 3 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 2 of 3 tracked threats
- [T1555](https://intel.threadlinqs.com/technique/T1555) Credentials from Password Stores — Credential Access — observed in 2 of 3 tracked threats
- [T1589.001](https://intel.threadlinqs.com/technique/T1589.001) Credentials — Reconnaissance — observed in 2 of 3 tracked threats
- [T1650](https://intel.threadlinqs.com/technique/T1650) Acquire Access — Resource Development — observed in 2 of 3 tracked threats
- [T1069](https://intel.threadlinqs.com/technique/T1069) Permission Groups Discovery — Discovery — observed in 1 of 3 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 1 of 3 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 1 of 3 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 1 of 3 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 1 of 3 tracked threats

## Tracked threats

- [Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims](https://intel.threadlinqs.com/threat/TL-2026-2047) — MEDIUM
- [Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS](https://intel.threadlinqs.com/threat/TL-2026-2028) — HIGH
- ["TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others](https://intel.threadlinqs.com/threat/TL-2026-2027) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/TheHatman
