Hacker sells stolen Azure employee data from Fortune 500 firms
A seller using the name TheHatman is advertising employee directory data allegedly stolen from at least nine large companies' Microsoft Azure and Entra ID environments, including McDonald's, Vodafone, Tata Consultancy Services and Kyndryl. The seller claims the records, more than 3.6 million in total, were pulled using compromised credentials and has been posting listings on cybercrime forums since late July. Several named companies, including TCS, Vodafone, Gap, HCLTech and Hexaware, have filed formal denials saying the data is old and does not point to a breach of current systems, but none has confirmed how the seller obtained it, and outside researchers say the leaked samples still look like genuine Azure directory exports. As of early September, no company has changed its position, no new victims have been confirmed, and the seller has not been identified or stopped.
- Started
- Jul 29, 2026
- Latest activity
- Aug 20, 2026
- Attributed to
- TheHatmanSuspected
- Where
- United States, United Kingdom, India
- Sectors
- Retail, Telecom, Technology, Multiple sectors
- Scale
- nine companies: McDonald's, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware
Current status
Searches through 2026-09-11 found no credible reports or official statements after 2026-08-30.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Security researchers and news outlets attribute the listings to a forum seller using the handle TheHatman, based on the seller's own posts; no law enforcement or victim confirmation.
Impact
A criminal seller claims to be offering more than 3.6 million employee directory records, including a claimed 1.7 million from McDonald's and over 800,000 from TCS, taken from corporate Azure and Entra ID tenants using stolen login credentials. Security researcher Hudson Rock says the leaked fields include employee IDs, job titles, manager and team information, and in some cases the names of accounts with Global Administrator access, which could help an attacker plan follow-up phishing or account-takeover attempts. Independent cybersecurity experts quoted in mid-to-late August said the record structure is consistent with real Azure and Entra exports and that even old directory data can carry risk, pushing back on companies calling the exposure harmless.
What to do
Employees of the named companies should watch for phishing emails that reference real internal details and report anything suspicious to their IT security team; there is no confirmed action needed from the general public.
Timeline
-
Aug 30, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 20, 2026
HCLTech and Hexaware Technologies filed stock exchange notices denying any current breach, joining TCS, Vodafone and Gap in disputing the seller's claims; cybersecurity experts told Moneycontrol the leaked data samples look structurally consistent with real Azure and Entra directory exports and warned that old data can still pose risk.
Emergingmoneycontrol.com -
Aug 19, 2026
Follow-up coverage noted the seller was continuing to advertise the dumps while several named companies argued the data was old and did not reflect a current breach.
Emergingtech.yahoo.com -
Aug 18, 2026
Gap said its preliminary investigation found the data in question is limited in scope, non-sensitive and dates back several years.
Emergingitpro.com -
Aug 18, 2026
Vodafone said the listed data is old employee information comparable to what would appear on a business card and confirmed no Vodafone customer data has been affected.
Emergingitpro.com -
Aug 18, 2026
Tata Consultancy Services filed a stock exchange disclosure denying any breach, saying the exposed data is more than four years old, limited to basic employee information, and that no customer data or operational systems were affected.
Emergingitpro.com -
Aug 17, 2026
Hudson Rock researchers published an analysis naming five more claimed victims beyond the original four: HCL Technologies, InterContinental Hotels Group, Gap, Hexaware Technologies and Wyndham Hotels, and assessed the data likely came from infostealer-compromised credentials rather than a single Azure vulnerability.
Emerginghudsonrock.com -
Aug 17, 2026
The Register and SecurityWeek reported the seller also listed Kyndryl and put the total claimed records at over 3.6 million.
Emergingtheregister.com -
Aug 7, 2026
Reports counted at least nine Fortune 500-level companies with data listed for sale by the same seller.
Emergingcybersecuritynews.com -
Jul 29, 2026
TheHatman began advertising stolen Azure/Entra ID employee data from McDonald's, Vodafone and Tata Consultancy Services on cybercrime forums.
Emergingesecurityplanet.com
Sources
- Crook hawks millions of records allegedly plundered from corporate Azure tenants The Register Aug 17, 2026
- GitLab bug can raise privileges eSecurityPlanet Jul 29, 2026
- Hacker claims 3.6 million Azure account records stolen from major companies BleepingComputer Aug 17, 2026
- Fortune 500 Companies Hit in Azure Data Theft Campaign SecurityWeek Aug 17, 2026
- McDonald's, Vodafone data leaked in Azure hack Cyber Security News Aug 7, 2026
- Hacker claims to have stolen millions of Azure customer records from McDonald's, Vodafone, Kyndryl, and others IT Pro Aug 18, 2026
- Hacker claims millions of records stolen from corporate Azure tenants Help Net Security Aug 18, 2026
- Millions of stolen records allegedly dumped online by mystery 'Hatman' hacker TechRadar (via MSN) Aug 18, 2026
- Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records Hudson Rock Aug 16, 2026
- Hackers dump millions of records from McDonald's, Vodafone, and Fortune 500 companies Cybernews Aug 17, 2026 unverified
- TCS, HCLTech, Hexaware deny dark web leaks but cyber experts aren't convinced Moneycontrol Aug 20, 2026
- Employee Databases from Multiple Fortune 500 Companies Affecting 3.6 Million Employees Listed on the Dark Web CPO Magazine Aug 24, 2026
- A hacker is selling stolen employee data from McDonald's, Gap and other giants Morning Overview Aug 24, 2026
- A Hacker Just Claimed 3.6 Million Azure Account Records Were Stolen The Tech Edvocate Aug 20, 2026
- 'Bigger Attacks Always Compromise Humans Than Systems' Rediff Aug 26, 2026
Related reports
- McDonald's, Vodafone data leaked in Azure hack Aug 7, 2026
- GitLab bug can raise privileges Jul 29, 2026