"TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others
"TheHatman" Azure/Entra Directory Exfiltration Campaign (TL-2026-2027) is a high-severity data breach, first published 2026-08-16. It is attributed to TheHatman with low confidence, affects McDonald's Corporation Microsoft Entra ID / Azure AD tenant directory, maps to 10 MITRE ATT&CK techniques (T1069.003, T1078.004, T1087.004), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-2027
- Threat ID
- TL-2026-2027
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-08-16
- Last reviewed
- 2026-08-16
- Attribution
- TheHatman
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- it-services, telecoms, hospitality, retail, quick-service-restaurants, technology-consulting, managed-infrastructure-services
- Target regions
- North America, Europe, Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 18
A threat actor using the handle "TheHatman" is selling internal Azure/Microsoft Entra ID employee-directory exports from at least nine Fortune 500-scale organizations on the BreachForums cybercrime forum, exposing PII, service-account data, and Global Administrator identities for roughly 3.6 million employees combined. Hudson Rock traced the root cause to Azure credentials harvested by infostealer malware and, in TCS's case, to a specific infostealer-infected machine in India; several named victims (TCS, HCLTech) dispute an active breach and characterize the exposed data as several years old.
How "TheHatman" Azure/Entra Directory Exfiltration Campaign works
Beginning in the days before August 16, 2026, a threat actor operating under the alias "TheHatman" began flooding the BreachForums cybercrime marketplace with internal employee-directory exports claimed to have been pulled directly from the Microsoft Azure/Entra ID tenants of nine large enterprises: McDonald's Corporation (~1.7M records), Tata Consultancy Services (~800K), Vodafone (~425K), HCLTech (~250K), InterContinental Hotels Group (~185K), Kyndryl (~170K), Gap Inc. (~80K), Hexaware Technologies (~20K), and Wyndham Hotels (~9K) — roughly 3.6 million employee records across IT services, telecommunications, hospitality, retail, and quick-service-restaurant sectors.
The exposed fields consistently include full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager/direct-report relationships, user group memberships, service-account entries, and — critically — listings of accounts holding the Global Administrator role, along with tenant-specific *.onmicrosoft.com structure. Cybercrime-intelligence firm Hudson Rock (via its Cavalier platform) independently reviewed the listings and found the data structurally consistent with genuine Azure directory exports, and separately identified compromised Azure Active Directory credentials tied to infostealer infections for most of the named victims — in TCS's case, tracing the exposed credential to a specific machine infected with infostealer malware in India.
TheHatman's own BreachForums listing for the TCS dataset (~800,000 records, with a ~6,000-record proof sample and buyer contact via Session, Tox, and Jabber) claims the tenant was accessed via password spraying combined with MFA-fatigue (push-bombing) attacks, a claim distinct from — but not necessarily exclusive of — the infostealer-credential root cause Hudson Rock identified; the exact initial-access chain has not been independently confirmed by any victim. A parallel 2,200-record sample published for the Kyndryl listing explicitly calls out accounts carrying the Global Administrator role, underscoring that the actor is marketing privileged-identity visibility, not just generic PII.
Victim response has been mixed and largely skeptical of an active, ongoing compromise. TCS filed a BSE stock-exchange disclosure on August 10, 2026 acknowledging the threat-intelligence alert but stating it found no credible evidence of a breach of its systems or customer environments, that the ~800,000-record claim exceeds its own ~590,000-person workforce, and that the sampled data appears to be more than four years old. HCLTech similarly disputed the claim, describing any genuinely exposed data as "limited and potentially years old," asserting no client-system impact, and noting mitigations it implemented roughly two years prior remain effective. Neither company has fully ruled out that older, previously unreported exposure underlies the current listings. McDonald's, Vodafone, IHG, Kyndryl, Gap, Hexaware, and Wyndham had not issued public statements addressing this specific campaign as of the primary reporting.
Regardless of whether the underlying data is current or several years old, the structured exposure of manager hierarchies, service-account naming, group memberships, and — especially — Global Administrator identities gives any purchaser a ready-made reconnaissance package for highly targeted Business Email Compromise, spear-phishing, and follow-on privilege-escalation attempts against nine large, high-profile enterprises simultaneously.
MITRE ATT&CK techniques used in TL-2026-2027
Discovery
T1069.003 Cloud Groups; T1087.004 Cloud Account
Initial Access
Credential Access
T1110.003 Password Spraying; T1555 Credentials from Password Stores; T1621 Multi-Factor Authentication Request Generation
Collection
Exfiltration
T1567 Exfiltration Over Web Service
Reconnaissance
Resource Development
Affected products and versions in "TheHatman" Azure/Entra Directory Exfiltration Campaign
- McDonald's Corporation — Microsoft Entra ID / Azure AD tenant directory
- Tata Consultancy Services (TCS) — Microsoft Entra ID / Azure AD tenant directory
- Vodafone — Microsoft Entra ID / Azure AD tenant directory
- HCLTech (HCL Technologies) — Microsoft Entra ID / Azure AD tenant directory
- InterContinental Hotels Group (IHG) — Microsoft Entra ID / Azure AD tenant directory
- Kyndryl — Microsoft Entra ID / Azure AD tenant directory
- Gap Inc. — Microsoft Entra ID / Azure AD tenant directory
- Hexaware Technologies — Microsoft Entra ID / Azure AD tenant directory
- Wyndham Hotels — Microsoft Entra ID / Azure AD tenant directory
Remediation for "TheHatman" Azure/Entra Directory Exfiltration Campaign
Immediate actions
- Treat all Microsoft Entra ID Global Administrator and privileged service-account credentials at potentially affected tenants as exposed and rotate them immediately.
- Audit Entra ID sign-in logs for anomalous authentication events (impossible travel, new device/IP for privileged accounts, MFA-fatigue push-approval patterns) covering at least the past several years given victims' claims the data may be old.
- Engage a cybercrime-intelligence / infostealer-log monitoring service (e.g., Hudson Rock Cavalier or equivalent) to check whether employee or third-party credentials for the organization appear in stealer-log marketplaces.
- Enforce re-authentication and step-up verification for any account matching names/emails/titles found in the leaked samples before granting further access changes.
Workarounds
- Temporarily restrict Azure/Entra admin-portal and Microsoft Graph API access to a VPN or known corporate IP allow-list while the scope and age of the exposed data is investigated.
Longer-term hardening
- Move all Global Administrator and other privileged Entra ID roles to phishing-resistant, number-matching MFA (FIDO2/passkeys) and eliminate SMS/push-only MFA that is vulnerable to fatigue attacks.
- Deploy Microsoft Entra ID Privileged Identity Management (PIM) so Global Administrator is a just-in-time, time-bound elevation rather than a standing assignment.
- Apply Conditional Access policies restricting Entra ID/Graph API administrative access to managed, compliant devices and known network locations.
- Establish continuous infostealer-credential monitoring as a standing control given that infostealer-sourced credentials were the common thread across most named victims in this campaign.
Timeline of "TheHatman" Azure/Entra Directory Exfiltration Campaign
- 'TheHatman' advertises approximately 800,000 TCS employee records on BreachForums, publishing a ~6,000-record sample and claiming access via password-spraying and MFA-fatigue attacks, with buyer contact offered via Session, Tox, and Jabber.
- TCS files a Bombay Stock Exchange (BSE) regulatory disclosure acknowledging threat-intelligence alerts about a claimed employee-data exposure tied to 'TheHatman', stating it found no credible evidence of a breach of its systems or customer environments.
- Indian financial media (Upstox) report on TCS's stock-exchange disclosure, noting TCS's position that the sampled data 'appears to be' more than four years old and that it has maintained strong safeguards against such attacks for over two years.
- TCS reiterates that the ~800,000-record claim exceeds its actual workforce of roughly 590,000 employees and maintains there is no indication of customer data or systems being impacted.
- HCLTech publicly disputes the leak claim, stating any genuinely exposed data is 'limited and potentially years old,' that no client systems were affected, and that security controls it implemented roughly two years earlier remain effective.
- A 2,200-record proof sample ('Kyndryl-sample-data-2200.csv') is published for the Kyndryl listing, explicitly identifying accounts flagged with the Global Administrator role among the exposed employee and service-account records.
- Hudson Rock's Cavalier cybercrime-intelligence platform ties the compromised Azure Active Directory credential used in the TCS listing to a specific machine infected with infostealer malware in India, and finds similar infostealer-sourced credential evidence linked to most of the other named victims.
- Hudson Rock/Infostealers.com publishes a consolidated report identifying nine named victims of TheHatman's Azure/Entra directory-sale campaign — McDonald's (~1.7M), TCS (~800K), Vodafone (~425K), HCLTech (~250K), IHG (~185K), Kyndryl (~170K), Gap (~80K), Hexaware (~20K), and Wyndham (~9K) records — and attributing the common root cause to Azure credentials harvested by infostealer malware.
Sources cited for "TheHatman" Azure/Entra Directory Exfiltration Campaign
- Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (McDonald's, Vodafone, Kyndryl & Others)
- Tata Consultancy Services: TCS flags data leak claims, finds no breach
- HCLTech and TCS: HCLTech says stolen data may be years-old after hacker's data breach claims
- TCS says leaked employee data 'appears to be' over four years old
- TCS data leak alert: IT firm says attackers claim potential employee data breach; will this impact customers?
Threats related to "TheHatman" Azure/Entra Directory Exfiltration Campaign
- Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims
- OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio Breaches
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
- ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and Businesses
Detection coverage for TL-2026-2027
As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2027 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.