"TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others — Threadlinqs Intelligence
As of 2026-08-16, "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others is a high-severity data breach threat attributed to TheHatman, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-2027 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Attribution: TheHatman · FINANCIAL
A threat actor using the handle "TheHatman" is selling internal Azure/Microsoft Entra ID employee-directory exports from at least nine Fortune 500-scale organizations on the BreachForums cybercrime
Beginning in the days before August 16, 2026, a threat actor operating under the alias "TheHatman" began flooding the BreachForums cybercrime marketplace with internal employee-directory exports claimed to have been pulled directly from the Microsoft Azure/Entra ID tenants of nine large enterprises: McDonald's Corporation (~1.7M records), Tata Consultancy Services (~800K), Vodafone (~425K), HCLTech (~250K), InterContinental Hotels Group (~185K), Kyndryl (~170K), Gap Inc. (~80K), Hexaware Technologies (~20K), and Wyndham Hotels (~9K) — roughly 3.6 million employee records across IT services, telecommunications, hospitality, retail, and quick-service-restaurant sectors.
The exposed fields consistently include full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager/direct-report relationships, user group memberships, service-account entries, and — critically — listings of accounts holding the Global Administrator role, along with tenant-specific *.onmicrosoft.com structure. Cybercrime-intelligence firm Hudson Rock (via its Cavalier platform) independently reviewed the listings and found the data structurally consistent with genuine Azure directory exports, and separately identified compromised Azure Active Directory credentials tied to infostealer infections for most of the named victims — in TCS's case, tracing the exposed credential to a specific machine infected with infostealer malware in India.
TheHatman's own BreachForums listing for the TCS dataset (~800,000 records, with a ~6,000-record proof sample and buyer contact via Session, Tox, and Jabber) claims the tenant was accessed via password spraying combined with MFA-fatigue (push-bombing) attacks, a claim distinct from — but not necessarily exclusive of — the infostealer-credential root cause Hudson Rock identified; the exact initial-access chain has not been independently confirmed by any victim. A parallel 2,200-record sample published for the Kyndryl listing explicitly calls out accounts carrying the Global Administrator role, underscoring that the actor is marketing privileged-identity visibility, not just generic PII.
Victim response has been mixed and largely skeptical of an active, ongoing compromise. TCS filed a BSE stock-exchange disclosure on August 10, 2026 acknowledging the threat-intelligence alert but stating it found no credible evidence of a breach of its systems or customer environments, that the ~800,000-record claim exceeds its own ~590,000-person workforce, and that the sampled data appears to be more than four years old. HCLTech similarly disputed the claim, describing any genuinely exposed data as "limited and potentially years old," asserting no client-system impact, and noting mitigations it implemented roughly two years prior remain effective. Neither company has fully ruled out that older, previously unreported exposure underlies the current listings. McDonald's, Vodafone, IHG, Kyndryl, Gap, Hexaware, and Wyndham had not issued public statements addressing this specific campaign as of the primary reporting.
Regardless of whether the underlying data is current or several years old, the structured exposure of manager hierarchies, service-account naming, group memberships, and — especially — Global Administrator identities gives any purchaser a ready-made reconnaissance package for highly targeted Business Email Compromise, spear-phishing, and follow-on privilege-escalation attempts against nine large, high-profile enterprises simultaneously.
Target sectors: it-services, telecoms, hospitality, retail, quick-service-restaurants, technology-consulting, managed-infrastructure-services
Target regions: North America, Europe, Asia, Global
Timeline
- TCS files a Bombay Stock Exchange (BSE) regulatory disclosure acknowledging threat-intelligence alerts about a claimed employee-data exposure tied to 'TheHatman', stating it found no credible evidence of a breach of its systems or customer environments.
- 'TheHatman' advertises approximately 800,000 TCS employee records on BreachForums, publishing a ~6,000-record sample and claiming access via password-spraying and MFA-fatigue attacks, with buyer contact offered via Session, Tox, and Jabber.
- Indian financial media (Upstox) report on TCS's stock-exchange disclosure, noting TCS's position that the sampled data 'appears to be' more than four years old and that it has maintained strong safeguards against such attacks for over two years.
- Hudson Rock/Infostealers.com publishes a consolidated report identifying nine named victims of TheHatman's Azure/Entra directory-sale campaign — McDonald's (~1.7M), TCS (~800K), Vodafone (~425K), HCLTech (~250K), IHG (~185K), Kyndryl (~170K), Gap (~80K), Hexaware (~20K), and Wyndham (~9K) records — and attributing the common root cause to Azure credentials harvested by infostealer malware.
- Hudson Rock's Cavalier cybercrime-intelligence platform ties the compromised Azure Active Directory credential used in the TCS listing to a specific machine infected with infostealer malware in India, and finds similar infostealer-sourced credential evidence linked to most of the other named victims.
- A 2,200-record proof sample ('Kyndryl-sample-data-2200.csv') is published for the Kyndryl listing, explicitly identifying accounts flagged with the Global Administrator role among the exposed employee and service-account records.
- HCLTech publicly disputes the leak claim, stating any genuinely exposed data is 'limited and potentially years old,' that no client systems were affected, and that security controls it implemented roughly two years earlier remain effective.
- TCS reiterates that the ~800,000-record claim exceeds its actual workforce of roughly 590,000 employees and maintains there is no indication of customer data or systems being impacted.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1589.001, T1650, T1555, T1110.003, T1621, T1078.004, T1087.004, T1069.003, T1119, T1567