Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims

Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra (TL-2026-2047) is a medium-severity data breach, first published 2026-08-17. It is attributed to TheHatman with low confidence, affects Microsoft Azure / Microsoft Entra ID (Azure Active Directory), maps to 10 MITRE ATT&CK techniques (T1069, T1078, T1087), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2047

Threat ID
TL-2026-2047
Severity
MEDIUM
Status
MONITORING
Category
DATA_BREACH
First published
2026-08-17
Last reviewed
2026-08-17
Attribution
TheHatman
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
retail, food-service, telecoms, information-technology-services, hospitality, technology-services, business-process-outsourcing
Target regions
North America, Europe, Asia, Global
Detection rules
9
Indicators of compromise
12

A threat actor using the alias 'TheHatman' has flooded underground cybercrime forums since July 31, 2026 with listings claiming theft of over 3.6 million employee/tenant directory records from at least nine Fortune-500-level organizations' Microsoft Azure/Entra ID tenants via compromised credentials, password spray, and MFA fatigue. Threat-intel firm Hudson Rock verified sample authenticity and traced some of the underlying compromised Azure AD credentials to infostealer infections on employee machines at TCS, HCL Technologies, Gap, and Kyndryl, though it does not confirm infostealers as the access vector at every organization. TCS and Gap Inc. publicly dispute the claims, stating they found no evidence of compromise and that the data appears several years old.

How Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra works

Beginning July 31, 2026, a threat actor operating under the alias 'TheHatman' began posting listings on underground cybercrime forums offering internal employee directory dumps allegedly exfiltrated directly from victim organizations' Microsoft Azure and Microsoft Entra ID (Azure Active Directory) tenants. By mid-August 2026 the actor's listings covered at least nine Fortune-500-level enterprises spanning IT services, hospitality, telecommunications, retail, and logistics: McDonald's Corporation (1.7M+ records), Tata Consultancy Services (800,000+), Vodafone Group (425,000+), HCL Technologies (250,000+), InterContinental Hotels Group (185,000+), Kyndryl (170,000+), Gap Inc. (80,000+), Hexaware Technologies (20,000+), and Wyndham Hotels & Resorts (9,000+) — a combined total exceeding 3.64 million records.

The actor claims the data was obtained by directly accessing victim Azure tenants using compromised credentials, password spraying, and MFA fatigue (push-notification bombing) attacks. The exposed data reportedly includes full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager/direct-report relationships, user group memberships, service account records, and Global Administrator identifiers — core Azure AD/Entra directory export fields.

Threat-intelligence firm Hudson Rock reviewed samples and assessed them as consistent with genuine corporate directory exports based on corporate email address formats and field structures, expressing 'high confidence' in authenticity. Independently, Hudson Rock's cybercrime intelligence platform identified compromised Azure AD credentials tied to infostealer malware infections on employee machines at several of the named organizations, including a machine infected in India holding stolen TCS Azure AD credentials, a compromised HCL Technologies employee credential (illustrating password-reuse risk), stolen Gap Inc. Microsoft credentials, and a Kyndryl-linked machine found to hold dozens of corporate credentials plus hundreds of sensitive browser session cookies. Hudson Rock explicitly cautions this does not establish infostealer infection as the confirmed initial-access vector at every named organization, and assessed that, given the scale of the organizations impacted, the campaign more likely stems from targeted exploitation of infostealer-derived credentials than a systemic Azure platform zero-day.

None of the named organizations have publicly confirmed compromise. Tata Consultancy Services stated it found 'no credible evidence of a breach,' that the data is 'at least four years old,' contains 'only basic employee information,' and that TCS deployed safeguards against such techniques more than two years ago. Gap Inc. stated it found 'no evidence to suggest that our corporate systems have been compromised' and that the data is 'limited in scope, non-sensitive, and dated back to several years ago.' BleepingComputer and other outlets were unable to independently verify the claims, and the precise initial-access vector and exfiltration method remain unconfirmed as of August 17, 2026. No CVE or Azure platform vulnerability has been identified or implicated; this is a credential/identity-based intrusion claim, not a software vulnerability.

Regardless of the disputed authenticity, Hudson Rock and other researchers note the exfiltrated data — particularly service account records and Global Administrator names — provides a reconnaissance roadmap for follow-on social engineering, spearphishing, and privilege-escalation attacks against the named organizations and their employees.

MITRE ATT&CK techniques used in TL-2026-2047

Discovery

T1069 Permission Groups Discovery; T1087 Account Discovery

Initial Access

T1078 Valid Accounts

Credential Access

T1110 Brute Force; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1621 Multi-Factor Authentication Request Generation

Collection

T1213 Data from Information Repositories

Reconnaissance

T1589 Gather Victim Identity Information

Resource Development

T1650 Acquire Access

Affected products and versions in Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra

  • Microsoft — Azure / Microsoft Entra ID (Azure Active Directory) enterprise tenant directory
    Vulnerable versions: N/A — claimed credential/identity-based unauthorized tenant access, not a software version vulnerability

Remediation for Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra

Immediate actions

  • Enforce phishing-resistant MFA (FIDO2/WebAuthn) for all Entra ID accounts, with priority on Global Administrator and other privileged/service accounts, and disable SMS/voice/push-only MFA fallback for those roles
  • Review Entra ID sign-in logs for anomalous password-spray indicators (single-source many-account low-and-slow authentication attempts, impossible-travel, and unusual MFA push-approval patterns) and force password resets on flagged accounts
  • Revoke and force re-issuance of session/refresh tokens for Global Administrator and other privileged roles tenant-wide to invalidate any stolen session cookies

Workarounds

  • Disable legacy/basic authentication protocols in Entra ID that can bypass modern Conditional Access and MFA enforcement
  • Restrict and audit third-party application/API permissions holding broad Microsoft Graph directory read scopes (User.Read.All, Directory.Read.All) via admin-consent workflows
  • Monitor dark-web/underground forum data broker listings for organizational directory data as an early-warning signal

Longer-term hardening

  • Deploy Conditional Access policies requiring compliant/managed devices and risk-based re-authentication for administrative and service-account sign-ins
  • Adopt Microsoft Authenticator number-matching and additional context (location, app) in MFA prompts to blunt MFA-fatigue/push-bombing attacks
  • Enable Continuous Access Evaluation (CAE) so stolen session tokens are invalidated in near-real time on risk signals
  • Deploy endpoint detection and response (EDR) tuned to identify infostealer malware behavior (bulk browser credential/cookie access) on employee endpoints before harvested Azure AD credentials can be reused

Timeline of Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra

  • Threat actor 'TheHatman' began posting listings on underground cybercrime forums offering internal Azure/Entra tenant employee directory dumps for sale.
  • TheHatman's forum listings had expanded to at least nine Fortune-500-level organizations across IT services, hospitality, telecommunications, retail, and logistics, totaling roughly 3.64 million claimed records.
  • Hudson Rock published analysis assessing sample authenticity with high confidence and linking compromised Azure AD credentials to infostealer infections on employee machines at TCS, HCL Technologies, Gap Inc., and Kyndryl.
  • BleepingComputer and other outlets reported they could not independently verify the claims; the initial-access vector and exfiltration method remained unconfirmed, and no other named organization (Vodafone, HCL, IHG, Kyndryl, Hexaware, Wyndham, McDonald's) had issued a public statement.
  • Gap Inc. publicly disputed the breach, stating it found no evidence its corporate systems were compromised and that the data is limited in scope, non-sensitive, and several years old.
  • Tata Consultancy Services publicly disputed the breach, stating it found no credible evidence of compromise, that the leaked data appears at least four years old and contains only basic employee information, and that safeguards against such techniques were deployed more than two years ago.
  • BleepingComputer, The Register, SecurityWeek, CyberNews, GBHackers, and other outlets published coverage of the claimed Azure/Entra tenant data theft campaign.

Sources cited for Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra

Threats related to Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra

Detection coverage for TL-2026-2047

As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2047 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats