Dormant High impact Data breach Checked 10h ago

Hacker sells stolen Azure employee data from Fortune 500 firms

A seller using the name TheHatman is advertising employee directory data allegedly stolen from at least nine large companies' Microsoft Azure and Entra ID environments, including McDonald's, Vodafone, Tata Consultancy Services and Kyndryl. The seller claims the records, more than 3.6 million in total, were pulled using compromised credentials and has been posting listings on cybercrime forums since late July. Several named companies, including TCS, Vodafone, Gap, HCLTech and Hexaware, have filed formal denials saying the data is old and does not point to a breach of current systems, but none has confirmed how the seller obtained it, and outside researchers say the leaked samples still look like genuine Azure directory exports. As of early September, no company has changed its position, no new victims have been confirmed, and the seller has not been identified or stopped.

Started
Jul 29, 2026
Latest activity
Aug 20, 2026
Attributed to
TheHatmanSuspected
Where
United States, United Kingdom, India
Sectors
Retail, Telecom, Technology, Multiple sectors
Scale
nine companies: McDonald's, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware

Current status

Searches through 2026-09-11 found no credible reports or official statements after 2026-08-30.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Security researchers and news outlets attribute the listings to a forum seller using the handle TheHatman, based on the seller's own posts; no law enforcement or victim confirmation.

Impact

A criminal seller claims to be offering more than 3.6 million employee directory records, including a claimed 1.7 million from McDonald's and over 800,000 from TCS, taken from corporate Azure and Entra ID tenants using stolen login credentials. Security researcher Hudson Rock says the leaked fields include employee IDs, job titles, manager and team information, and in some cases the names of accounts with Global Administrator access, which could help an attacker plan follow-up phishing or account-takeover attempts. Independent cybersecurity experts quoted in mid-to-late August said the record structure is consistent with real Azure and Entra exports and that even old directory data can carry risk, pushing back on companies calling the exposure harmless.

What to do

Employees of the named companies should watch for phishing emails that reference real internal details and report anything suspicious to their IT security team; there is no confirmed action needed from the general public.

Timeline

  1. Aug 30, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Aug 20, 2026

    HCLTech and Hexaware Technologies filed stock exchange notices denying any current breach, joining TCS, Vodafone and Gap in disputing the seller's claims; cybersecurity experts told Moneycontrol the leaked data samples look structurally consistent with real Azure and Entra directory exports and warned that old data can still pose risk.

    Emergingmoneycontrol.com
  3. Aug 19, 2026

    Follow-up coverage noted the seller was continuing to advertise the dumps while several named companies argued the data was old and did not reflect a current breach.

    Emergingtech.yahoo.com
  4. Aug 18, 2026

    Gap said its preliminary investigation found the data in question is limited in scope, non-sensitive and dates back several years.

    Emergingitpro.com
  5. Aug 18, 2026

    Vodafone said the listed data is old employee information comparable to what would appear on a business card and confirmed no Vodafone customer data has been affected.

    Emergingitpro.com
  6. Aug 18, 2026

    Tata Consultancy Services filed a stock exchange disclosure denying any breach, saying the exposed data is more than four years old, limited to basic employee information, and that no customer data or operational systems were affected.

    Emergingitpro.com
  7. Aug 17, 2026

    Hudson Rock researchers published an analysis naming five more claimed victims beyond the original four: HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies and Wyndham Hotels, and assessed the data likely came from infostealer-compromised credentials rather than a single Azure vulnerability.

    Emerginghudsonrock.com
  8. Aug 17, 2026

    The Register and SecurityWeek reported the seller also listed Kyndryl and put the total claimed records at over 3.6 million.

    Emergingtheregister.com
  9. Aug 7, 2026

    Reports counted at least nine Fortune 500-level companies with data listed for sale by the same seller.

    Emergingcybersecuritynews.com
  10. Jul 29, 2026

    TheHatman began advertising stolen Azure/Entra ID employee data from McDonald's, Vodafone and Tata Consultancy Services on cybercrime forums.

    Emergingesecurityplanet.com

Sources

Related reports