Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims — Threadlinqs Intelligence
As of 2026-08-17, Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims is a medium-severity data breach threat attributed to TheHatman, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 12 indicators of compromise.
Threat ID: TL-2026-2047 · Severity: MEDIUM · Status: MONITORING · Category: DATA_BREACH
Attribution: TheHatman · FINANCIAL
A threat actor using the alias 'TheHatman' has flooded underground cybercrime forums since July 31, 2026 with listings claiming theft of over 3.6 million employee/tenant directory records from at
Beginning July 31, 2026, a threat actor operating under the alias 'TheHatman' began posting listings on underground cybercrime forums offering internal employee directory dumps allegedly exfiltrated directly from victim organizations' Microsoft Azure and Microsoft Entra ID (Azure Active Directory) tenants. By mid-August 2026 the actor's listings covered at least nine Fortune-500-level enterprises spanning IT services, hospitality, telecommunications, retail, and logistics: McDonald's Corporation (1.7M+ records), Tata Consultancy Services (800,000+), Vodafone Group (425,000+), HCL Technologies (250,000+), InterContinental Hotels Group (185,000+), Kyndryl (170,000+), Gap Inc. (80,000+), Hexaware Technologies (20,000+), and Wyndham Hotels & Resorts (9,000+) — a combined total exceeding 3.64 million records.
The actor claims the data was obtained by directly accessing victim Azure tenants using compromised credentials, password spraying, and MFA fatigue (push-notification bombing) attacks. The exposed data reportedly includes full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager/direct-report relationships, user group memberships, service account records, and Global Administrator identifiers — core Azure AD/Entra directory export fields.
Threat-intelligence firm Hudson Rock reviewed samples and assessed them as consistent with genuine corporate directory exports based on corporate email address formats and field structures, expressing 'high confidence' in authenticity. Independently, Hudson Rock's cybercrime intelligence platform identified compromised Azure AD credentials tied to infostealer malware infections on employee machines at several of the named organizations, including a machine infected in India holding stolen TCS Azure AD credentials, a compromised HCL Technologies employee credential (illustrating password-reuse risk), stolen Gap Inc. Microsoft credentials, and a Kyndryl-linked machine found to hold dozens of corporate credentials plus hundreds of sensitive browser session cookies. Hudson Rock explicitly cautions this does not establish infostealer infection as the confirmed initial-access vector at every named organization, and assessed that, given the scale of the organizations impacted, the campaign more likely stems from targeted exploitation of infostealer-derived credentials than a systemic Azure platform zero-day.
None of the named organizations have publicly confirmed compromise. Tata Consultancy Services stated it found 'no credible evidence of a breach,' that the data is 'at least four years old,' contains 'only basic employee information,' and that TCS deployed safeguards against such techniques more than two years ago. Gap Inc. stated it found 'no evidence to suggest that our corporate systems have been compromised' and that the data is 'limited in scope, non-sensitive, and dated back to several years ago.' BleepingComputer and other outlets were unable to independently verify the claims, and the precise initial-access vector and exfiltration method remain unconfirmed as of August 17, 2026. No CVE or Azure platform vulnerability has been identified or implicated; this is a credential/identity-based intrusion claim, not a software vulnerability.
Regardless of the disputed authenticity, Hudson Rock and other researchers note the exfiltrated data — particularly service account records and Global Administrator names — provides a reconnaissance roadmap for follow-on social engineering, spearphishing, and privilege-escalation attacks against the named organizations and their employees.
Target sectors: retail, food-service, telecoms, information-technology-services, hospitality, technology-services, business-process-outsourcing
Target regions: North America, Europe, Asia, Global
Timeline
- Threat actor 'TheHatman' began posting listings on underground cybercrime forums offering internal Azure/Entra tenant employee directory dumps for sale.
- Hudson Rock published analysis assessing sample authenticity with high confidence and linking compromised Azure AD credentials to infostealer infections on employee machines at TCS, HCL Technologies, Gap Inc., and Kyndryl.
- TheHatman's forum listings had expanded to at least nine Fortune-500-level organizations across IT services, hospitality, telecommunications, retail, and logistics, totaling roughly 3.64 million claimed records.
- BleepingComputer, The Register, SecurityWeek, CyberNews, GBHackers, and other outlets published coverage of the claimed Azure/Entra tenant data theft campaign.
- Tata Consultancy Services publicly disputed the breach, stating it found no credible evidence of compromise, that the leaked data appears at least four years old and contains only basic employee information, and that safeguards against such techniques were deployed more than two years ago.
- Gap Inc. publicly disputed the breach, stating it found no evidence its corporate systems were compromised and that the data is limited in scope, non-sensitive, and several years old.
- BleepingComputer and other outlets reported they could not independently verify the claims; the initial-access vector and exfiltration method remained unconfirmed, and no other named organization (Vodafone, HCL, IHG, Kyndryl, Hexaware, Wyndham, McDonald's) had issued a public statement.
Related threats
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
- Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortion
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000
- Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service Marketplaces
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 12 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, MEDIUM, threat intelligence, cybersecurity, T1589, T1650, T1078, T1110, T1621, T1539, T1555, T1087, T1069, T1213