Security5 distinct publishers3 min readPublished Updated
A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A threat actor is selling data said to have been taken directly from the Azure tenants of several Fortune 500 organizations, and the listings name McDonald's Corporation, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels [1][2]. According to the seller, who uses the moniker TheHatman, the data was exfiltrated from Azure/Entra instances using leaked credentials [2][3]. That is the part worth sitting with: no breach of the identity provider is claimed, and none is needed.
Hudson Rock, which examined the dumps, says the contents are internal employee directories that appear legitimate, based on identified email addresses and on field names matching Azure directory exports [4]. The counts disclosed for individual victims are large. McDonald's is the biggest at over 1.7 million records, followed by TCS at 800,000, Vodafone at 425,000, HCL Technologies at 250,000 and IHG at 185,000 [5][6][7][8][9]. Those five figures alone total at least 3.36 million records [16]. Four of the nine named organizations have no record count attached in the listings, so the real total is unknown [17].
The field list is the story. Across all the affected tenant dumps, Hudson Rock says the leaked fields consistently include foundational corporate directory attributes [10]: employee names, corporate email addresses, physical addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts and highly privileged account records [11]. That is not a customer table. That is the shape of an organization, including who reports to whom and which accounts can do damage.
Hudson Rock calls the exposure of service accounts and global admin names particularly concerning, describing it as a direct roadmap for subsequent social engineering, spear-phishing or targeted privilege escalation [12]. The firm also says the data lets attackers map internal reporting structures and high-value targets, and supports convincing spear-phishing and business email compromise [15]. Anyone who has run a BEC tabletop knows the expensive variable is plausibility, and a manager chain plus an employee ID supplies it cheaply.
On origin, Hudson Rock's assessment is that credentials compromised in a targeted infostealer campaign were likely used to pull the data, and it says it identified stolen credentials linked to most of the affected organizations [13]. The victimology points the same way, according to the company, and the campaign spans IT services, hospitality, telecommunications, retail and logistics [13][14]. Read plainly, this is commodity credential theft converted into tenant-level identity data at scale, then packaged per-brand for resale.
The operational implication is unpleasant for anyone who treats identity as infrastructure rather than as data. Directory contents have historically been considered low-sensitivity because they are visible to employees anyway. These listings price them otherwise, and the export is a legitimate administrative function that will not look like intrusion in most logs.
What to watch: whether any of the nine named companies confirms unauthorized directory access, since as reported the claims rest on the seller's assertion plus Hudson Rock's analysis [1][3][4]. Watch also for whether the privileged and service accounts named in the dumps show up in later intrusions at the same organizations, which is the test of whether this data is inventory or an operational precursor [11][12]. And watch the four unquantified victims: if their counts surface, the campaign's scale changes rather than its character [17].
Ranked by verification strength, evidence, and original report placement.
According to the threat actor, the data was exfiltrated from Azure/Entra instances using leaked credentials.
Hudson Rock says the data contains internal employee directories that, based on the identified email addresses and field names that match Azure directory exports, appear legitimate.
A threat actor is selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations.
Using the moniker 'TheHatman', the threat actor has been offering millions of records apparently stolen from McDonald's Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels.
Hudson Rock notes: "The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations."
Hudson Rock says the stolen data poses an immediate threat because it allows attackers to map internal reporting structures and high-value targets, and enables convincing spear-phishing and business email compromise (BEC) attacks.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Sample forensics solid, scope unconfirmed
Authenticity of at least the McDonald's data is well evidenced: an offline forensic read of the 8,000-row sample found tenant-internal .onmicrosoft.com addresses, McDonald's-controlled domains, genuine encoding damage and a matching real-world restaurant record, and a cybercrime intelligence firm independently judged the directories legitimate across dumps. What is not evidenced is the volume, the age of the data, the intrusion vector, and impact at eight of the nine named companies; one outlet states plainly it could not independently verify the data, and two named victims dispute that any breach of their systems occurred.
Listings and samples real, victim impact open
The observable activity is concrete and repeated: nine listings over roughly sixteen days, each with a verification sample and an identical 19-column export schema, spanning five sectors. But confirmed downstream impact is thin — no buyer, price or exploitation is reported, no listed company has confirmed a compromise, and two say the data is years old and non-sensitive, which limits how far the campaign can be treated as materially landed.
Breach framing outruns confirmed impact
Headline framing of Fortune 500 companies being 'hit' in an Azure data theft campaign runs ahead of what the sources establish. The seller's aggregate and per-tenant counts are unverified and one analysis notes the direct incentive to round them up; the intrusion vector is described as unknown by one outlet even as another presents infostealer attribution as settled; the analyzed sample holds no passwords or hashes, so account takeover is not the exposure; and two named victims report old, basic, non-sensitive data with no system compromise. The gap is moderate rather than severe because the underlying artifacts do appear to be genuine directory exports.
Seller inflation, vendor visibility, victim downplay
Every voice in this cluster has a stake. The seller profits from larger-sounding volumes and one analysis flags that incentive explicitly. The intelligence firm whose findings anchor two of the three articles sells infostealer credential intelligence, which aligns with the infostealer attribution it advances. The named victims have disclosure and market incentives to minimize, and TCS's statement was filed with a stock exchange. One outlet's page also carries a security vendor report promotion alongside the reporting. These are visible in the sources rather than inferred.
Three publishers agree on facts, differ on certainty
Confidence is moderate: three publishers within a single day converge on the actor alias, the nine-company list, the Entra export schema and the social-engineering risk profile, and one contributes primary file-level analysis plus victim statements. It is held back by reliance on a single intelligence vendor for cross-dump authenticity, no Microsoft or platform-side comment, no confirmation from seven of nine named companies, and unresolved questions about data age, volume and access vector.
security
Storm-0501's first move is deleting your resource locks, not encrypting your disks1 distinct publisher
security
Microsoft says the patch window has closed. Read the fine print on what runs in the gap.1 distinct publisher
build
Same-day GPT-5.6 on Azure kills the parity argument, leaving auth and residency to decide1 distinct publisher
product
Microsoft never announced a China exit. Five years of filings did it instead1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
bleepingcomputer.com
1 article · August 17, 2026
helpnetsecurity.com
1 article · August 18, 2026
scworld.com
1 article · August 18, 2026
securityaffairs.com
1 article · August 17, 2026
securityweek.com
1 article · August 16, 2026