A threat actor using the name “TheHatman” is attempting to sell approximately 3.64 million records allegedly collected from the Microsoft Azure and Entra environments of nine major international organisations.
The advertised information is linked to McDonald’s, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware Technologies and Wyndham Hotels & Resorts.
Samples examined by security researchers reportedly contain employee names, corporate email addresses, telephone numbers, job titles, departments, office locations and internal identifiers. Some of the material is also said to identify service accounts, security-group memberships and users assigned powerful administrative roles.
The listings could represent a significant exposure of corporate identity data, but the attacker’s claims remain only partially verified. It is unclear when each dataset was collected, whether every record originated in an active Microsoft tenant or how much of the information remains current.
TCS, Vodafone and Gap have challenged the suggestion that their systems were recently compromised. The companies said the information associated with them appeared to be several years old or limited to basic employee details.
There is also no evidence that TheHatman exploited a vulnerability in Microsoft Azure or Entra. The available information points instead towards stolen credentials, hijacked sessions, abused cloud permissions or a mixture of older datasets collected through different sources.
Alleged Data Spans Nine Global Companies
The criminal began advertising the directories on underground forums around the end of July, with additional listings appearing during the first half of August.
McDonald’s accounts for the largest advertised collection at more than 1.7 million records. The seller claims to have another:
- 800,000 records associated with TCS,
- 425,000 from Vodafone,
- 250,000 from HCL Technologies,
- 185,000 from InterContinental Hotels Group
- 170,000 from Kyndryl.
The remaining listings allegedly contain more than 80,000 Gap records, 20,000 Hexaware records and 9,000 entries connected to Wyndham Hotels.
Together, the claims amount to approximately 3.64 million records. That number comes from the alleged attacker and has not been independently confirmed.
It also should not be interpreted as 3.64 million current employees. Large enterprise directories commonly contain former workers, contractors, franchise personnel, suppliers, business partners, guest users, shared mailboxes, automated applications and service accounts. One person may have several separate directory objects, while disabled accounts can remain visible for compliance or operational reasons.
This is particularly relevant to the claim of 1.7 million McDonald’s records. The total may include franchise-related identities, former workers, contractors, business partners, guests, duplicates and non-human accounts rather than 1.7 million members of the company’s current workforce.
TheHatman reportedly supplied samples so prospective buyers could examine the data. That does not necessarily mean the complete collections have been freely dumped online. Available reporting indicates that the full datasets are primarily being offered for sale, although samples have been exposed on criminal forums.
The listings appeared across DarkForum and sites operating as alternatives or successors to BreachForums. DarkForum is described by threat-intelligence specialists as a Russian-speaking marketplace used to sell databases, stolen accounts
Samples Resemble Entra Directory Exports
Hudson Rock, a threat-intelligence company specialising in information-stealing malware, examined samples publicised by the seller. It concluded that portions of the data were highly likely to be authentic because their structure resembled information exported from Microsoft cloud directories.
The samples reportedly contained corporate email domains, tenant-specific “onmicrosoft.com” addresses and fields consistent with Microsoft Entra ID. The information allegedly includes names, employee identifiers, email addresses, telephone numbers, job titles, departments, workplace addresses, managers, direct reports and group memberships.
Some listings appear more sensitive than ordinary employee contact directories. They allegedly include the names of Global Administrators, other privileged users and service accounts.
A Global Administrator can hold extensive authority across an Entra environment. Identifying such accounts does not give a criminal administrative access, but it supplies a focused list of high-value targets for phishing, password-reset fraud and help-desk impersonation.
Service accounts create a different form of risk. They are often used by applications, automation tools and older systems rather than individual employees. Because they operate in the background, they can receive less scrutiny than human accounts and may retain access long after their original purpose has changed.
The apparent authenticity of a sample does not validate every statement made by its seller. Criminals frequently combine old breaches, public information and newly acquired records before presenting the result as a fresh intrusion. Theto be established separately
We could not independently verify the full datasets or confirm the method used to obtain them. Hudson Rock likewise said it had not conclusively established the intrusion vector.
Why This Is Not Necessarily an Azure Breach
The presence of Microsoft directory data has led some reports to describe the incident as an Azure breach. That description risks implying that an attacker penetrated Microsoft’s underlying cloud infrastructure or discovered a vulnerability affecting Azure customers generally.
There is currently no evidence that either occurred.
A Microsoft Entra tenant is an organisation’s cloud identity environment. It contains users, groups, applications, service principals, administrative roles and the relationships used to determine who can access connected resources.
Microsoft operates the platform, but each customer manages its identities, permissions and security policies. If an attacker obtains a valid employee login, steals a browser session or abuses an overprivileged application, the criminal may be able to access information inside that customer’s tenant without breaching Microsoft itself.
Directory access also does not automatically mean the attacker reached customer databases,the contents of files stored in Microsoft 365
The actual impact depends on the permissions assigned to the compromised identity, the applications it can use and what the intruder did after authentication.
No technical evidence of an Azure or Entra zero-day has been released. Microsoft has not announced a platform-level compromise connected to the advertisements.
Hudson Rock considers targeted identity compromise more likely than a systemic cloud vulnerability. If TheHatman possessed an easily exploitable Entra flaw, researchers would expect to see a much broader range of victims, including smaller organisations, rather than a concentrated list of high-value global enterprises.
Stolen Credentials and Sessions Are Leading Possibilities
TheHatman claims to have used compromised credentials, but the initial
One possibility is information-stealing malware. Infostealers infect endpoints and collect saved passwords, browser cookies, authentication tokens, autofill information and other secrets. The stolen material is packaged into logs that can be searched or sold to criminals looking for access to particular companies.
Hudson Rock said its databases contained compromised Microsoft cloud credentials associated with most of the named organisations. However, it could not connect a particular credential or malware infection to TheHatman’s alleged activity.
That distinction matters. The existence of compromised credentials belonging to an organisation does not prove that those credentials were used in this campaign.
Session theft presents an additional risk. After a user successfully signs in and completes multifactor authentication, the browser or application receives tokens that maintain the authenticated session. If malware or an adversary-in-the-middle phishing service steals those tokens, a criminal may attempt to replay them from another system.
Depending on the token, application and security policies involved, this can allow an attacker to impersonate the user without entering the password or completing a new MFA challenge.
Microsoft says password attacks still account for the overwhelming majority of the identity attacks it observes, but token theft has been increasing as organisations strengthen authentication. Its guidance estimates that token-theft incidents reached approximately 39,000 a day, while adversary-in-the-middle phishing rose by 146% over the period assessed in the company’s 2024 defence report.Microsoft’s token-security guidancerecommends phishing-resistant credentials, hardened endpoints, device- and risk-based Conditional Access, and device-bound tokens where supported.
Other plausible routes into the directories include phishing, credential stuffing, password spraying, MFA fatigue, compromised contractors and third-party applications with excessive directory-reading privileges.
None of those methods has been confirmed as the common cause of the nine listings.
TCS Challenges the Attacker’s Account
Tata Consultancy Services issued one of the most detailed responses after information associated with the company appeared for sale.
In a regulatory notification, TCS said it investigated the threat-intelligence alert and found no credible evidence that its systems or customer environments had been breached. It said the referenced information appeared to be more than four years old and limited to basic employee details.
The company also reported no indication that customer data, customer systems or its operational infrastructure had been affected.
According to TCS, the seller claimed to have used password spraying and MFA fatigue. TCS said it had maintained safeguards against those techniques for more than two years and that the controls remained effective.
Password spraying involves testing one or a small number of commonly used passwords against many accounts. By limiting the number of attempts made against each identity, the attacker tries to remain below conventional lockout thresholds.
MFA fatigue, sometimes called push bombing, occurs after a criminal has obtained or guessed a user’s password. The attacker repeatedly attempts to sign in, generating authentication requests on the victim’s phone. The aim is to persuade the user to approve a request accidentally or to stop the stream of notifications.
TCS’s statement raises the possibility that its dataset came from an older incident, a previous directory export, a third-party application or another historicaltions
Vodafone and Gap Point to Older Information
Vodafone also said its assessment indicated that the advertised records consisted of old employee information comparable to details available through an address list or business card.
The company said it had identified no Vodafone customer data and no resulting impact. The listing therefore should not be interpreted as evidence that the personal, payment or telecommunications data of Vodafone customers was exposed.
Gap similarly said its preliminary investigation found no evidence that its corporate systems had been compromised. The retailer described the information as limited in scope, non-sensitive and several years old.
The responses undermine the idea that all nine listings represent simultaneous or recent attacks. The seller may instead have assembled a mixture of new material, historical corporate directories and information obtained from unrelated sources.
Other named organisations had not released comparably detailed public findings at the time of reporting. A lack of immediate confirmation is not proof of compromise: identity incidents can require lengthy reviews of authentication logs, third-party applications, former employee records and historical data.
Old Employee Information Can Still Be Weaponised
The age of a directory substantially affects the severity of an incident, but it does not make the information harmless.
Corporate email formats, office locations and department names can remain unchanged for years. Former employees may maintain relationships with current staff, and historical reporting structures can help an attacker understand how an organisation operates.
The records can also be refreshed using company websites, professional networking platforms and more recent breaches.
Names, job titles and reporting relationships allow criminals to identify employees working in payroll, finance, human resources, procurement, IT support and cybersecurity. Telephone numbers provide a route for voice phishing, while email addresses support targeted impersonation and malicious login campaigns.
For example, an attacker could identify an employee authorised to pay a supplier, determine the employee’s manager and imitate either the manager or the supplier. Referencing genuine departments, office locations and colleagues makes a fraudulent request significantly more convincing.
Exposed administrator names could help criminals target the people with the greatest ability to change access policies. Service-account details could reveal older or overlooked identities that warrant further investigation.
The directory may therefore operate as reconnaissance for a second intrusion rather than being the final objective. It could be purchased by ransomware affiliates, business-email-compromise groups, initial-access brokers or criminals specialising in support-desk manipulation.
Cloud Applications Create Another Route to Data
One of the more significant possibilities is the abuse of OAuth applications or third-party integrations.
Organisations frequently connect cloud applications to Microsoft 365 and Entra. Those applications may receive permission to read user profiles, group information, mail, files or other corporate resources.
If an attacker compromises a legitimate integration—or persuades a user or administrator to approve a malicious one—the application can provide a route to organisational data that is separate from an ordinary interactive login.
This access can sometimes persist after a user changes a password because the application has its own permissions, credentials or consent grant.
Microsoft previously documented financially motivated attacks in which criminals used compromised accounts to create or modify OAuth applications. The applications were then used for phishing, cryptocurrency mining and business-email-compromise activity. In one investigated operation, malicious applications helped distribute more than 927,000 phishing messages.Microsoft Threat Intelligencesaid the activity demonstrated how attackers can abuse cloud identities and application permissions after gaining an initial foothold.
There is no evidence that TheHatman used the same technique. The earlier Microsoft campaign illustrates why investigators must examine application consent and service-principal activity rather than limiting their review to employee passwords.
What Investigators Need to Determine
The central issue is whether the listings represent nine recent intrusions, nine historical datasets or a mixture assembled through several unrelated methods.
Investigators will need to compare samples with their live and historical directories. Creation dates, disabled users, unique internal attributes and decoy accounts could help establish when and where the records were collected.
Entra sign-in and audit logs should be examined for unusual enumeration of users, groups, roles and service principals. Investigators should look for large Microsoft Graph queries, unfamiliar devices, unexpected geographic locations, anonymising infrastructure and successful logins occurring after waves of failed password attempts.
Changes to authentication methods, new application secrets, unfamiliar certificates, unexpected consent grants and modifications to privileged roles may indicate that access extended beyond a simple directory export.
Security teams must also determine whether the attacker performed a one-time download or retained persistent access. Those scenarios involve very different levels of continuing risk.
Password changes alone may be insufficient where sessions or application permissions have been compromised. Organisations may need to revoke refresh tokens, terminate active sessions, remove malicious applications, rotate secrets and review every privileged identity connected to the suspected account.
Reducing the Risk of Credential and Token Theft
Microsoft recommends that organisations adopt phishing-resistant authentication, including FIDO2 security keys and passkeys, rather than relying solely on approval-based push notifications.
Number matching in Microsoft Authenticator can reduce conventional push fatigue by requiring a user to enter a number displayed during the sign-in attempt. It does not prevent every adversary-in-the-middle attack and cannot invalidate a token that has already been stolen.
Token Protection can reduce replay attacks by cryptographically binding supported sign-in tokens to the device on which they were issued. A stolen bound token should then be rejected when presented from a different device.
Coverage remains dependent on the operating system, application and resource. According toMicrosoft’s current documentation, protection is generally available for supported native Windows applications accessing Exchange Online, SharePoint Online, Teams, Azure Virtual Desktop and Windows 365. Some macOS, iOS and browser-based Azure Resource Manager scenarios remain in preview or are not supported.
Organisations should introduce the control through a pilot deployment and use report-only Conditional Access policies before broad enforcement to avoid disrupting unsupported applications.
Other priorities include removing dormant accounts, reviewing guest access, restricting ordinary users’ visibility of sensitive directory attributes, enforcing least privilege and auditing third-party application permissions.
Security teams should pay particular attention to non-human identities. Service accounts and service principals need defined owners, limited privileges, credential rotation and regular access reviews.
Employees whose details appear in the samples should be warned to expect convincing phishing messages, fraudulent calls and impersonation attempts. Finance and support-desk personnel should independently verify requests to change payment information, reset MFA or register new devices.
Authentic-Looking Data, but an Unproven Breach Narrative
TheHatman’s listings combine credible warning signs with unresolved questions.
Researchers say portions of the advertised material resemble genuine Microsoft Entra directory information. The reported exposure of employee relationships, service accounts and administrator identities would give criminals a useful blueprint for further attacks.
However, the seller’s totals, timelines and intrusion claims remain unverified. TCS, Vodafone and Gap have all indicated that information linked to them is old or that their investigations found no evidence of a recent corporate-system compromise.
There is likewise no evidence of a common vulnerability in Microsoft Azure or Entra.
The incident is therefore most accurately described as the attempted sale of approximately 3.64 million allegedly stolen corporate directory records—not a confirmed compromise of Microsoft’s cloud and not yet nine independently verified breaches.
What the campaign does demonstrate is the growing security importance of cloud identity data. A directory does not need to contain passwords to be dangerous. When it exposes who works for an organisation, who reports to whom, which accounts run critical services and which identities hold administrative power, it can provide everything an attacker needs to design the next stage of an intrusion.