TechNewsReel
Live

Threat Actor 'TheHatman' Sells Millions of Azure Records from Global Giants

Security researchers warn that infostealer malware likely fueled the exfiltration of employee data from nine major corporations, including McDonald's and Vodafone.

TechNewsReel Newsroom · August 17, 2026

A threat actor operating under the name 'TheHatman' is advertising the sale of millions of employee records allegedly stolen from the Microsoft Azure environments of nine major corporations. The breach exposes a massive volume of corporate directory data, raising alarms over the security of cloud-based identity management for Fortune 500 companies.

According to analysis by security researchers at Hudson Rock, the stolen data is highly likely to be authentic based on the email domains and field structures. The alleged haul is extensive, featuring approximately 1.7 million records from McDonald's, 800,000 from Tata Consultancy Services (TCS), 425,000 from Vodafone, and 250,000 from HCL Technologies. Other impacted organizations include Gap, Kyndryl, IHG Hotels & Resorts, Wyndham Hotels & Resorts, and Hexaware Technologies. The exfiltrated information includes employee IDs, job titles, and reporting structures.

The Attack Vector

While the exact method of exfiltration remains unconfirmed, Hudson Rock suggests the breach did not stem from a systemic zero-day vulnerability within Microsoft Azure. Instead, researchers believe the campaign likely resulted from the targeted exploitation of infostealer malware infections. By harvesting credentials from infected endpoints, the attacker was able to access and export directory services data from Microsoft Azure/Entra ID.

Tata Consultancy Services (TCS) has contested the severity of the leak. In a statement, the company noted that its investigation found no credible evidence of a breach of its systems or customer environments, asserting that the referenced information appears to be more than four years old and limited to basic employee details.

Industry Implications

This incident underscores the critical risk posed by infostealer malware, which transforms individual endpoint compromises into wide-scale corporate intelligence leaks. Directory data is particularly valuable to attackers because it provides a comprehensive map of a company's internal hierarchy. This allows threat actors to identify high-value targets for subsequent spear-phishing campaigns or social engineering attacks, turning a data leak into a springboard for deeper network penetration.

What to Watch

Security teams are now monitoring for an increase in targeted phishing attempts against the affected organizations. While the core data haul has been analyzed, the full extent of the attacker's access to these Azure tenants remains a primary concern. Industry observers will be watching for further evidence of whether the attacker successfully pivoted from directory access to more sensitive administrative controls within the compromised environments.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.