Published · 6d agoSecurity3 min read
Stolen logins, not a SaaS breach: nine enterprises' Entra directories are now for sale
A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- A threat actor is selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations.
- Using the moniker 'TheHatman', the threat actor has been offering millions of records apparently stolen from McDonald's Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.
- According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials.
- Hudson Rock says the data contains internal employee directories that, based on the identified email addresses and field names that match Azure directory exports, appear legitimate.
- The McDonald's dump is the largest, containing over 1.7 million records.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A threat actor is selling data said to have been taken directly from the Azure tenants of several Fortune 500 organizations, and the listings name McDonald's Corporation, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels [1][2]. According to the seller, who uses the moniker TheHatman, the data was exfiltrated from Azure/Entra instances using leaked credentials [2][3]. That is the part worth sitting with: no breach of the identity provider is claimed, and none is needed.
Hudson Rock, which examined the dumps, says the contents are internal employee directories that appear legitimate, based on identified email addresses and on field names matching Azure directory exports [4]. The counts disclosed for individual victims are large. McDonald's is the biggest at over 1.7 million records, followed by TCS at 800,000, Vodafone at 425,000, HCL Technologies at 250,000 and IHG at 185,000 [5][6][7][8][9]. Those five figures alone total at least 3.36 million records [16]. Four of the nine named organizations have no record count attached in the listings, so the real total is unknown [17].
The field list is the story. Across all the affected tenant dumps, Hudson Rock says the leaked fields consistently include foundational corporate directory attributes [10]: employee names, corporate email addresses, physical addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts and highly privileged account records [11]. That is not a customer table. That is the shape of an organization, including who reports to whom and which accounts can do damage.
Hudson Rock calls the exposure of service accounts and global admin names particularly concerning, describing it as a direct roadmap for subsequent social engineering, spear-phishing or targeted privilege escalation [12]. The firm also says the data lets attackers map internal reporting structures and high-value targets, and supports convincing spear-phishing and business email compromise [15]. Anyone who has run a BEC tabletop knows the expensive variable is plausibility, and a manager chain plus an employee ID supplies it cheaply.
On origin, Hudson Rock's assessment is that credentials compromised in a targeted infostealer campaign were likely used to pull the data, and it says it identified stolen credentials linked to most of the affected organizations [13]. The victimology points the same way, according to the company, and the campaign spans IT services, hospitality, telecommunications, retail and logistics [13][14]. Read plainly, this is commodity credential theft converted into tenant-level identity data at scale, then packaged per-brand for resale.
The operational implication is unpleasant for anyone who treats identity as infrastructure rather than as data. Directory contents have historically been considered low-sensitivity because they are visible to employees anyway. These listings price them otherwise, and the export is a legitimate administrative function that will not look like intrusion in most logs.
What to watch: whether any of the nine named companies confirms unauthorized directory access, since as reported the claims rest on the seller's assertion plus Hudson Rock's analysis [1][3][4]. Watch also for whether the privileged and service accounts named in the dumps show up in later intrusions at the same organizations, which is the test of whether this data is inventory or an operational precursor [11][12]. And watch the four unquantified victims: if their counts surface, the campaign's scale changes rather than its character [17].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A threat actor is selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations.
ReportedView cited source - [2]
Using the moniker 'TheHatman', the threat actor has been offering millions of records apparently stolen from McDonald's Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.
ReportedView cited source - [3]
According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials.
ReportedView cited source - [4]
Hudson Rock says the data contains internal employee directories that, based on the identified email addresses and field names that match Azure directory exports, appear legitimate.
ReportedView cited source - [5]
The McDonald's dump is the largest, containing over 1.7 million records.
ReportedView cited source
Sources & coverage · 5 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityweek.comIonut Arghire6d agoFortune 500 Companies Hit in Azure Data Theft Campaign
- securityaffairs.comPierluigi Paganini6d agoMcDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
- bleepingcomputer.comIonut Ilascu



