Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims
Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra (TL-2026-2047) is a medium-severity data breach, first published 2026-08-17. It is attributed to TheHatman with low confidence, affects Microsoft Azure / Microsoft Entra ID (Azure Active Directory), maps to 10 MITRE ATT&CK techniques (T1069, T1078, T1087), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-2047
- Threat ID
- TL-2026-2047
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- DATA_BREACH
- First published
- 2026-08-17
- Last reviewed
- 2026-08-17
- Attribution
- TheHatman
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- retail, food-service, telecoms, information-technology-services, hospitality, technology-services, business-process-outsourcing
- Target regions
- North America, Europe, Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 12
A threat actor using the alias 'TheHatman' has flooded underground cybercrime forums since July 31, 2026 with listings claiming theft of over 3.6 million employee/tenant directory records from at least nine Fortune-500-level organizations' Microsoft Azure/Entra ID tenants via compromised credentials, password spray, and MFA fatigue. Threat-intel firm Hudson Rock verified sample authenticity and traced some of the underlying compromised Azure AD credentials to infostealer infections on employee machines at TCS, HCL Technologies, Gap, and Kyndryl, though it does not confirm infostealers as the access vector at every organization. TCS and Gap Inc. publicly dispute the claims, stating they found no evidence of compromise and that the data appears several years old.
How Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra works
Beginning July 31, 2026, a threat actor operating under the alias 'TheHatman' began posting listings on underground cybercrime forums offering internal employee directory dumps allegedly exfiltrated directly from victim organizations' Microsoft Azure and Microsoft Entra ID (Azure Active Directory) tenants. By mid-August 2026 the actor's listings covered at least nine Fortune-500-level enterprises spanning IT services, hospitality, telecommunications, retail, and logistics: McDonald's Corporation (1.7M+ records), Tata Consultancy Services (800,000+), Vodafone Group (425,000+), HCL Technologies (250,000+), InterContinental Hotels Group (185,000+), Kyndryl (170,000+), Gap Inc. (80,000+), Hexaware Technologies (20,000+), and Wyndham Hotels & Resorts (9,000+) — a combined total exceeding 3.64 million records.
The actor claims the data was obtained by directly accessing victim Azure tenants using compromised credentials, password spraying, and MFA fatigue (push-notification bombing) attacks. The exposed data reportedly includes full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager/direct-report relationships, user group memberships, service account records, and Global Administrator identifiers — core Azure AD/Entra directory export fields.
Threat-intelligence firm Hudson Rock reviewed samples and assessed them as consistent with genuine corporate directory exports based on corporate email address formats and field structures, expressing 'high confidence' in authenticity. Independently, Hudson Rock's cybercrime intelligence platform identified compromised Azure AD credentials tied to infostealer malware infections on employee machines at several of the named organizations, including a machine infected in India holding stolen TCS Azure AD credentials, a compromised HCL Technologies employee credential (illustrating password-reuse risk), stolen Gap Inc. Microsoft credentials, and a Kyndryl-linked machine found to hold dozens of corporate credentials plus hundreds of sensitive browser session cookies. Hudson Rock explicitly cautions this does not establish infostealer infection as the confirmed initial-access vector at every named organization, and assessed that, given the scale of the organizations impacted, the campaign more likely stems from targeted exploitation of infostealer-derived credentials than a systemic Azure platform zero-day.
None of the named organizations have publicly confirmed compromise. Tata Consultancy Services stated it found 'no credible evidence of a breach,' that the data is 'at least four years old,' contains 'only basic employee information,' and that TCS deployed safeguards against such techniques more than two years ago. Gap Inc. stated it found 'no evidence to suggest that our corporate systems have been compromised' and that the data is 'limited in scope, non-sensitive, and dated back to several years ago.' BleepingComputer and other outlets were unable to independently verify the claims, and the precise initial-access vector and exfiltration method remain unconfirmed as of August 17, 2026. No CVE or Azure platform vulnerability has been identified or implicated; this is a credential/identity-based intrusion claim, not a software vulnerability.
Regardless of the disputed authenticity, Hudson Rock and other researchers note the exfiltrated data — particularly service account records and Global Administrator names — provides a reconnaissance roadmap for follow-on social engineering, spearphishing, and privilege-escalation attacks against the named organizations and their employees.
MITRE ATT&CK techniques used in TL-2026-2047
Discovery
T1069 Permission Groups Discovery; T1087 Account Discovery
Initial Access
Credential Access
T1110 Brute Force; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1621 Multi-Factor Authentication Request Generation
Collection
T1213 Data from Information Repositories
Reconnaissance
T1589 Gather Victim Identity Information
Resource Development
Affected products and versions in Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra
- Microsoft — Azure / Microsoft Entra ID (Azure Active Directory) enterprise tenant directory
Vulnerable versions: N/A — claimed credential/identity-based unauthorized tenant access, not a software version vulnerability
Remediation for Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra
Immediate actions
- Enforce phishing-resistant MFA (FIDO2/WebAuthn) for all Entra ID accounts, with priority on Global Administrator and other privileged/service accounts, and disable SMS/voice/push-only MFA fallback for those roles
- Review Entra ID sign-in logs for anomalous password-spray indicators (single-source many-account low-and-slow authentication attempts, impossible-travel, and unusual MFA push-approval patterns) and force password resets on flagged accounts
- Revoke and force re-issuance of session/refresh tokens for Global Administrator and other privileged roles tenant-wide to invalidate any stolen session cookies
Workarounds
- Disable legacy/basic authentication protocols in Entra ID that can bypass modern Conditional Access and MFA enforcement
- Restrict and audit third-party application/API permissions holding broad Microsoft Graph directory read scopes (User.Read.All, Directory.Read.All) via admin-consent workflows
- Monitor dark-web/underground forum data broker listings for organizational directory data as an early-warning signal
Longer-term hardening
- Deploy Conditional Access policies requiring compliant/managed devices and risk-based re-authentication for administrative and service-account sign-ins
- Adopt Microsoft Authenticator number-matching and additional context (location, app) in MFA prompts to blunt MFA-fatigue/push-bombing attacks
- Enable Continuous Access Evaluation (CAE) so stolen session tokens are invalidated in near-real time on risk signals
- Deploy endpoint detection and response (EDR) tuned to identify infostealer malware behavior (bulk browser credential/cookie access) on employee endpoints before harvested Azure AD credentials can be reused
Timeline of Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra
- Threat actor 'TheHatman' began posting listings on underground cybercrime forums offering internal Azure/Entra tenant employee directory dumps for sale.
- TheHatman's forum listings had expanded to at least nine Fortune-500-level organizations across IT services, hospitality, telecommunications, retail, and logistics, totaling roughly 3.64 million claimed records.
- Hudson Rock published analysis assessing sample authenticity with high confidence and linking compromised Azure AD credentials to infostealer infections on employee machines at TCS, HCL Technologies, Gap Inc., and Kyndryl.
- BleepingComputer and other outlets reported they could not independently verify the claims; the initial-access vector and exfiltration method remained unconfirmed, and no other named organization (Vodafone, HCL, IHG, Kyndryl, Hexaware, Wyndham, McDonald's) had issued a public statement.
- Gap Inc. publicly disputed the breach, stating it found no evidence its corporate systems were compromised and that the data is limited in scope, non-sensitive, and several years old.
- Tata Consultancy Services publicly disputed the breach, stating it found no credible evidence of compromise, that the leaked data appears at least four years old and contains only basic employee information, and that safeguards against such techniques were deployed more than two years ago.
- BleepingComputer, The Register, SecurityWeek, CyberNews, GBHackers, and other outlets published coverage of the claimed Azure/Entra tenant data theft campaign.
Sources cited for Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra
- Hacker claims 3.6 million Azure account records stolen from major companies
- Crook hawks millions of records allegedly plundered from corporate Azure tenants
- Fortune 500 Companies Hit in Azure Data Theft Campaign
- Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (McDonald's, Vodafone, Kyndryl & Others)
- TCS, HCL, Hexaware named in global Azure directory data leak linked to infostealers
- McDonald's, Vodafone Hit by Azure Credential Theft Campaign Exposing Millions of Enterprise Records
- Hackers dump millions of records from McDonald's, Vodafone, and Fortune 500 companies
- McDonald's, Vodafone Hit in Massive Azure Credential Theft Campaign
- Azure Cloud Credential Theft leads to Data Breach of McDonald's and Vodafone
Threats related to Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
- Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortion
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000
- Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service Marketplaces
Detection coverage for TL-2026-2047
As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2047 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.