Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS

Azure Credential Theft Campaign Exposes Millions of (TL-2026-2028) is a high-severity data breach, first published 2026-08-16. It is attributed to TheHatman with medium confidence, affects McDonald's Corporation Microsoft Entra ID (Azure AD) tenant directory, maps to 13 MITRE ATT&CK techniques (T1069.003, T1078.004, T1087.004), and is covered by 9 detection rules and 13 indicators of compromise.

Key facts for TL-2026-2028

Threat ID
TL-2026-2028
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-08-16
Last reviewed
2026-08-16
Attribution
TheHatman
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
retail, it-services, telecoms, hospitality, logistics
Target regions
North America, Europe, Asia
Detection rules
9
Indicators of compromise
13

A threat actor operating under the alias "TheHatman" is flooding underground cybercrime forums with Azure Entra ID directory data stolen from nine major enterprises — McDonald's, TCS, Vodafone, HCL Technologies, IHG, Kyndryl, Gap Inc., Hexaware, and Wyndham — totaling roughly 3.6 million employee/service-account records. Hudson Rock traced the access for at least four of the nine victims (TCS, Gap Inc., HCL Technologies, Kyndryl) to infostealer-harvested Azure AD credentials and session cookies; the attacker separately claims password spraying and MFA fatigue against TCS's tenant. TCS has publicly disputed the breach, stating it found no evidence of compromise and that the sample data appears to be over four years old.

How Azure Credential Theft Campaign Exposes Millions of works

Beginning in the week leading up to 2026-08-16, a threat actor using the handle "TheHatman" began advertising bulk Microsoft Entra ID (Azure Active Directory) directory exports from nine global enterprises on underground cybercrime forums. The listings span roughly 3.6 million combined records: McDonald's (~1.7M), Tata Consultancy Services (~800K), Vodafone (~425K), HCL Technologies (~250K), InterContinental Hotels Group (~185K), Kyndryl (~170K), Gap Inc. (~80K), Hexaware Technologies (~20K), and Wyndham Hotels & Resorts (~9K).

Each dataset reportedly contains full names, corporate email addresses (including tenant-specific `.onmicrosoft.com` structures), phone numbers, physical addresses, employee IDs, job titles, departments, manager/reporting-structure assignments, service-account details, user group memberships, access/group mapping data, and — most critically — Global Administrator account listings, along with tenant-specific credential material.

Hudson Rock's cybercrime intelligence platform reviewed sample data and assessed it as highly credible, citing corporate email domains and field structures that align precisely with standard Azure directory export formats. Hudson Rock traced compromised Azure AD credentials tied to infostealer infections to at least four of the nine victims: a TCS employee device infected in India; Gap Inc.; HCL Technologies; and a Kyndryl-linked machine found to contain "dozens of corporate credentials and hundreds of sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account." The precise access vector for the remaining five organizations (McDonald's, Vodafone, IHG, Hexaware, Wyndham) is not confirmed in public reporting; researchers describe it as "not conclusive" and cite phishing campaigns yielding administrative access, weak/absent MFA enforcement, and third-party API/integration abuse with excessive read privileges as other plausible vectors alongside infostealer credential theft.

For the TCS listing specifically, the seller separately claimed the ~800,000-record dataset (with a ~6,000-record public sample) was obtained via password spraying and MFA fatigue (push-bombing) against TCS's Entra ID tenant, and sought a negotiable price for the full dataset. TCS filed a regulatory/exchange disclosure on 2026-08-10 stating it found "no credible evidence of a breach" of its systems or customer environments, that the sampled data "appears to be" more than four years old and consists only of basic employee fields, and that its anti-password-spraying and anti-MFA-fatigue safeguards have been in place and effective for over two years. TCS's claimed workforce (~590,000) is notably smaller than the ~800,000 records advertised, a discrepancy TCS did not address. TCS said it is continuing to monitor and will act on new evidence; it has not disclosed employee-notification or law-enforcement plans. This dispute does not affect Hudson Rock's independent infostealer-based findings for the other three corroborated victims (Gap Inc., HCL Technologies, Kyndryl), or the fourth infostealer-linked victim, TCS itself — Hudson Rock's infostealer evidence and TCS's public denial are not mutually exclusive, since infostealer-harvested credentials can predate the stale data TCS describes.

No CVE, malware family name, or network/file IOC (IP, domain, hash) has been published for this campaign as of this writing — the exposure stems from stolen identity/session material and directory-service abuse rather than a software vulnerability. Researchers assess the exposed directory data as directly weaponizable for business email compromise, targeted spear-phishing, privilege-escalation attempts against the identified Global Administrator accounts, and as a reconnaissance foothold for follow-on ransomware initial-access operations against the nine affected organizations.

MITRE ATT&CK techniques used in TL-2026-2028

Discovery

T1069.003 Permission Groups Discovery: Cloud Groups; T1087.004 Account Discovery: Cloud Account

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1566 Phishing

Persistence

T1078.004 Valid Accounts: Cloud Accounts

Credential Access

T1110.003 Brute Force: Password Spraying; T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1621 Multi-Factor Authentication Request Generation

Collection

T1119 Automated Collection

lateral-movement

T1550.001 Use Alternate Authentication Material: Application Access Token; T1550.004 Use Alternate Authentication Material: Web Session Cookie

Reconnaissance

T1589.001 Gather Victim Identity Information: Credentials

Impact

T1657 Financial Theft

Affected products and versions in Azure Credential Theft Campaign Exposes Millions of

  • McDonald's Corporation — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~1.7M employee directory records advertised as exfiltrated
  • Tata Consultancy Services (TCS) — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~800K employee directory records advertised as exfiltrated (TCS disputes breach; says sample data is 4+ years old)
  • Vodafone — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~425K employee directory records advertised as exfiltrated
  • HCL Technologies — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~250K employee directory records advertised as exfiltrated
  • InterContinental Hotels Group (IHG) — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~185K employee directory records advertised as exfiltrated
  • Kyndryl — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~170K employee directory records advertised as exfiltrated
  • Gap Inc. — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~80K employee directory records advertised as exfiltrated
  • Hexaware Technologies — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~20K employee directory records advertised as exfiltrated
  • Wyndham Hotels & Resorts — Microsoft Entra ID (Azure AD) tenant directory
    Vulnerable versions: ~9K employee directory records advertised as exfiltrated

Remediation for Azure Credential Theft Campaign Exposes Millions of

Immediate actions

  • Force password reset and revoke all active sessions/refresh tokens for Global Administrator and other privileged Entra ID accounts across the nine confirmed tenants (McDonald's, TCS, Vodafone, HCL, IHG, Kyndryl, Gap Inc., Hexaware, Wyndham)
  • Audit and revoke third-party application/API registrations in Entra ID that hold excessive directory read privileges, including OAuth app access tokens
  • Hunt endpoint and sign-in logs for indicators of infostealer infection — anomalous session-cookie reuse, sign-ins from unexpected devices/locations/ASNs tied to the accounts named in Hudson Rock's findings
  • Review Entra ID sign-in logs for password-spraying signatures (low-and-slow failed auth across many accounts) and repeated MFA push prompts (MFA fatigue) consistent with the attacker's claimed TCS TTP

Workarounds

  • Require step-up MFA re-authentication for high-privilege directory operations (e.g., Global Admin role activation) via Privileged Identity Management (PIM)
  • Restrict third-party OAuth application consent to admin-approved apps only until the API permission audit is complete
  • Enable smart lockout / IP-based throttling in Entra ID to blunt password-spraying attempts against large employee populations

Longer-term hardening

  • Enforce phishing-resistant MFA (FIDO2/passkeys) for all Entra ID accounts, prioritizing Global Administrator and other privileged roles, and replace push-based MFA with number-matching or phishing-resistant methods to blunt MFA fatigue attacks
  • Deploy Conditional Access policies requiring compliant/managed devices and enforce token binding to reduce session-cookie replay/theft impact
  • Adopt Continuous Access Evaluation and shorten refresh-token lifetimes for privileged and service accounts
  • Stand up routine monitoring of infostealer-log marketplaces and cybercrime forums for exposed corporate credentials tied to the organization's domains

Weaknesses (CWE) in Azure Credential Theft Campaign Exposes Millions of

CWE-287, CWE-522, CWE-284, CWE-307

Timeline of Azure Credential Theft Campaign Exposes Millions of

  • TheHatman begins flooding underground cybercrime forums with Azure Entra ID directory dumps for multiple Fortune 500 tenants, per subsequent reporting describing activity spanning 'the past week' before the 2026-08-16 disclosure.
  • TCS files a regulatory/exchange disclosure stating it found 'no credible evidence of a breach' of its systems or customer environments, that the ~6,000-record public sample 'appears to be' more than four years old, and that the attacker's claimed technique — password spraying and MFA fatigue against its Entra ID tenant — has been mitigated by controls in place and effective for over two years.
  • Cyber Security News and InfoStealers.com publish public reporting on the campaign, summarizing Hudson Rock's findings across the nine confirmed victim organizations.
  • Hudson Rock reviews sample datasets and assesses the leaked data as highly credible, citing corporate email domains and field structures matching standard Azure directory export formats; researchers state it is 'not conclusive' how the campaign was carried out across all nine victims.
  • TheHatman advertises approximately 9,000 Wyndham Hotels & Resorts employee records.
  • TheHatman advertises approximately 20,000 Hexaware Technologies employee records.
  • TheHatman advertises approximately 80,000 Gap Inc. employee records, linked by Hudson Rock to infostealer-compromised credentials.
  • TheHatman advertises approximately 170,000 Kyndryl employee records, including employee accounts, service accounts, and Entra ID directory objects; Hudson Rock identifies a compromised device holding dozens of corporate credentials and hundreds of session cookies, including direct access to a Kyndryl Azure AD account.
  • TheHatman advertises approximately 185,000 InterContinental Hotels Group (IHG) employee records.
  • TheHatman advertises approximately 250,000 HCL Technologies employee records, among the companies Hudson Rock links to infostealer-compromised Azure credentials.
  • TheHatman advertises approximately 425,000 Vodafone employee directory records.
  • TheHatman advertises approximately 800,000 Tata Consultancy Services (TCS) employee records (a workforce-exceeding figure TCS did not address) with a ~6,000-record public sample; Hudson Rock ties access to an infostealer-infected device belonging to a TCS employee in India, while the seller separately claims password spraying and MFA fatigue as the intrusion method.
  • TheHatman advertises approximately 1.7 million McDonald's employee directory records purportedly exported from McDonald's Azure Entra ID tenant.
  • Cyber Security News reports that TheHatman has been flooding underground cybercrime forums with Azure Entra ID directory dumps 'over the past week,' citing Hudson Rock research.

Sources cited for Azure Credential Theft Campaign Exposes Millions of

Threats related to Azure Credential Theft Campaign Exposes Millions of

Detection coverage for TL-2026-2028

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2028 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats