"TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others

"TheHatman" Azure/Entra Directory Exfiltration Campaign (TL-2026-2027) is a high-severity data breach, first published 2026-08-16. It is attributed to TheHatman with low confidence, affects McDonald's Corporation Microsoft Entra ID / Azure AD tenant directory, maps to 10 MITRE ATT&CK techniques (T1069.003, T1078.004, T1087.004), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2027

Threat ID
TL-2026-2027
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-08-16
Last reviewed
2026-08-16
Attribution
TheHatman
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
it-services, telecoms, hospitality, retail, quick-service-restaurants, technology-consulting, managed-infrastructure-services
Target regions
North America, Europe, Asia, Global
Detection rules
9
Indicators of compromise
18

A threat actor using the handle "TheHatman" is selling internal Azure/Microsoft Entra ID employee-directory exports from at least nine Fortune 500-scale organizations on the BreachForums cybercrime forum, exposing PII, service-account data, and Global Administrator identities for roughly 3.6 million employees combined. Hudson Rock traced the root cause to Azure credentials harvested by infostealer malware and, in TCS's case, to a specific infostealer-infected machine in India; several named victims (TCS, HCLTech) dispute an active breach and characterize the exposed data as several years old.

How "TheHatman" Azure/Entra Directory Exfiltration Campaign works

Beginning in the days before August 16, 2026, a threat actor operating under the alias "TheHatman" began flooding the BreachForums cybercrime marketplace with internal employee-directory exports claimed to have been pulled directly from the Microsoft Azure/Entra ID tenants of nine large enterprises: McDonald's Corporation (~1.7M records), Tata Consultancy Services (~800K), Vodafone (~425K), HCLTech (~250K), InterContinental Hotels Group (~185K), Kyndryl (~170K), Gap Inc. (~80K), Hexaware Technologies (~20K), and Wyndham Hotels (~9K) — roughly 3.6 million employee records across IT services, telecommunications, hospitality, retail, and quick-service-restaurant sectors.

The exposed fields consistently include full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager/direct-report relationships, user group memberships, service-account entries, and — critically — listings of accounts holding the Global Administrator role, along with tenant-specific *.onmicrosoft.com structure. Cybercrime-intelligence firm Hudson Rock (via its Cavalier platform) independently reviewed the listings and found the data structurally consistent with genuine Azure directory exports, and separately identified compromised Azure Active Directory credentials tied to infostealer infections for most of the named victims — in TCS's case, tracing the exposed credential to a specific machine infected with infostealer malware in India.

TheHatman's own BreachForums listing for the TCS dataset (~800,000 records, with a ~6,000-record proof sample and buyer contact via Session, Tox, and Jabber) claims the tenant was accessed via password spraying combined with MFA-fatigue (push-bombing) attacks, a claim distinct from — but not necessarily exclusive of — the infostealer-credential root cause Hudson Rock identified; the exact initial-access chain has not been independently confirmed by any victim. A parallel 2,200-record sample published for the Kyndryl listing explicitly calls out accounts carrying the Global Administrator role, underscoring that the actor is marketing privileged-identity visibility, not just generic PII.

Victim response has been mixed and largely skeptical of an active, ongoing compromise. TCS filed a BSE stock-exchange disclosure on August 10, 2026 acknowledging the threat-intelligence alert but stating it found no credible evidence of a breach of its systems or customer environments, that the ~800,000-record claim exceeds its own ~590,000-person workforce, and that the sampled data appears to be more than four years old. HCLTech similarly disputed the claim, describing any genuinely exposed data as "limited and potentially years old," asserting no client-system impact, and noting mitigations it implemented roughly two years prior remain effective. Neither company has fully ruled out that older, previously unreported exposure underlies the current listings. McDonald's, Vodafone, IHG, Kyndryl, Gap, Hexaware, and Wyndham had not issued public statements addressing this specific campaign as of the primary reporting.

Regardless of whether the underlying data is current or several years old, the structured exposure of manager hierarchies, service-account naming, group memberships, and — especially — Global Administrator identities gives any purchaser a ready-made reconnaissance package for highly targeted Business Email Compromise, spear-phishing, and follow-on privilege-escalation attempts against nine large, high-profile enterprises simultaneously.

MITRE ATT&CK techniques used in TL-2026-2027

Discovery

T1069.003 Cloud Groups; T1087.004 Cloud Account

Initial Access

T1078.004 Cloud Accounts

Credential Access

T1110.003 Password Spraying; T1555 Credentials from Password Stores; T1621 Multi-Factor Authentication Request Generation

Collection

T1119 Automated Collection

Exfiltration

T1567 Exfiltration Over Web Service

Reconnaissance

T1589.001 Credentials

Resource Development

T1650 Acquire Access

Affected products and versions in "TheHatman" Azure/Entra Directory Exfiltration Campaign

  • McDonald's Corporation — Microsoft Entra ID / Azure AD tenant directory
  • Tata Consultancy Services (TCS) — Microsoft Entra ID / Azure AD tenant directory
  • Vodafone — Microsoft Entra ID / Azure AD tenant directory
  • HCLTech (HCL Technologies) — Microsoft Entra ID / Azure AD tenant directory
  • InterContinental Hotels Group (IHG) — Microsoft Entra ID / Azure AD tenant directory
  • Kyndryl — Microsoft Entra ID / Azure AD tenant directory
  • Gap Inc. — Microsoft Entra ID / Azure AD tenant directory
  • Hexaware Technologies — Microsoft Entra ID / Azure AD tenant directory
  • Wyndham Hotels — Microsoft Entra ID / Azure AD tenant directory

Remediation for "TheHatman" Azure/Entra Directory Exfiltration Campaign

Immediate actions

  • Treat all Microsoft Entra ID Global Administrator and privileged service-account credentials at potentially affected tenants as exposed and rotate them immediately.
  • Audit Entra ID sign-in logs for anomalous authentication events (impossible travel, new device/IP for privileged accounts, MFA-fatigue push-approval patterns) covering at least the past several years given victims' claims the data may be old.
  • Engage a cybercrime-intelligence / infostealer-log monitoring service (e.g., Hudson Rock Cavalier or equivalent) to check whether employee or third-party credentials for the organization appear in stealer-log marketplaces.
  • Enforce re-authentication and step-up verification for any account matching names/emails/titles found in the leaked samples before granting further access changes.

Workarounds

  • Temporarily restrict Azure/Entra admin-portal and Microsoft Graph API access to a VPN or known corporate IP allow-list while the scope and age of the exposed data is investigated.

Longer-term hardening

  • Move all Global Administrator and other privileged Entra ID roles to phishing-resistant, number-matching MFA (FIDO2/passkeys) and eliminate SMS/push-only MFA that is vulnerable to fatigue attacks.
  • Deploy Microsoft Entra ID Privileged Identity Management (PIM) so Global Administrator is a just-in-time, time-bound elevation rather than a standing assignment.
  • Apply Conditional Access policies restricting Entra ID/Graph API administrative access to managed, compliant devices and known network locations.
  • Establish continuous infostealer-credential monitoring as a standing control given that infostealer-sourced credentials were the common thread across most named victims in this campaign.

Timeline of "TheHatman" Azure/Entra Directory Exfiltration Campaign

  • 'TheHatman' advertises approximately 800,000 TCS employee records on BreachForums, publishing a ~6,000-record sample and claiming access via password-spraying and MFA-fatigue attacks, with buyer contact offered via Session, Tox, and Jabber.
  • TCS files a Bombay Stock Exchange (BSE) regulatory disclosure acknowledging threat-intelligence alerts about a claimed employee-data exposure tied to 'TheHatman', stating it found no credible evidence of a breach of its systems or customer environments.
  • Indian financial media (Upstox) report on TCS's stock-exchange disclosure, noting TCS's position that the sampled data 'appears to be' more than four years old and that it has maintained strong safeguards against such attacks for over two years.
  • TCS reiterates that the ~800,000-record claim exceeds its actual workforce of roughly 590,000 employees and maintains there is no indication of customer data or systems being impacted.
  • HCLTech publicly disputes the leak claim, stating any genuinely exposed data is 'limited and potentially years old,' that no client systems were affected, and that security controls it implemented roughly two years earlier remain effective.
  • A 2,200-record proof sample ('Kyndryl-sample-data-2200.csv') is published for the Kyndryl listing, explicitly identifying accounts flagged with the Global Administrator role among the exposed employee and service-account records.
  • Hudson Rock's Cavalier cybercrime-intelligence platform ties the compromised Azure Active Directory credential used in the TCS listing to a specific machine infected with infostealer malware in India, and finds similar infostealer-sourced credential evidence linked to most of the other named victims.
  • Hudson Rock/Infostealers.com publishes a consolidated report identifying nine named victims of TheHatman's Azure/Entra directory-sale campaign — McDonald's (~1.7M), TCS (~800K), Vodafone (~425K), HCLTech (~250K), IHG (~185K), Kyndryl (~170K), Gap (~80K), Hexaware (~20K), and Wyndham (~9K) records — and attributing the common root cause to Azure credentials harvested by infostealer malware.

Sources cited for "TheHatman" Azure/Entra Directory Exfiltration Campaign

Threats related to "TheHatman" Azure/Entra Directory Exfiltration Campaign

Detection coverage for TL-2026-2027

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2027 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats