Marcus Chen
August 29, 2026
13 min read
A cybercriminal operating under the alias “TheHatman” is selling roughly 3.6 million employee-directory records allegedly pulled from the Microsoft Azure and Entra ID tenants of nine large companies, according to cybercrime intelligence firm Hudson Rock. The victim list includes McDonald’s, Vodafone, Tata Consultancy Services (TCS), Kyndryl, HCL Technologies, InterContinental Hotels Group (IHG), Gap Inc., Hexaware Technologies and Wyndham Hotels, based on reporting from BleepingComputer and Help Net Security published between August 17 and August 23, 2026.
The incident adds to a fast-moving run of 2026 cybersecurity threats that have kept enterprise security teams on edge all year. Unlike most headline breaches this year, this one carries no CVE number and no confirmed platform exploit. Researchers who reviewed the data say it was obtained through compromised employee credentials, likely harvested by infostealer malware, then used to log into legitimate Azure and Entra ID accounts and export directory data through Microsoft’s own APIs. That distinction matters: it turns a routine identity-hygiene failure into a mass data exposure event spanning fast food, telecom, IT outsourcing, hospitality and retail sectors at once.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
TheHatman Claims 3.6 Million Azure Records From Nine Companies
The seller first surfaced on a cybercrime forum in mid-August 2026, advertising directory dumps described as pulled directly from corporate Azure tenants. Hudson Rock’s review, cited by BleepingComputer, found the samples consistent with genuine Entra ID directory exports: real email domains, correctly formatted employee IDs, internal .onmicrosoft.com tenant structures, and in some cases the names of service accounts and global administrator accounts.
McDonald’s tops the list with an estimated 1.7 million records, the largest single dataset in the campaign. TCS follows with roughly 800,000 records, Vodafone with about 425,000, HCL Technologies with around 250,000, and IHG with close to 185,000. Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels round out the remaining tenants, with Kyndryl’s dataset estimated near 170,000 records and Gap’s near 80,000, according to the same reporting relayed by Help Net Security.
The data fields on offer reportedly include employee names, corporate email addresses, internal employee IDs, phone numbers and, in some tenants, physical addresses. That is a narrower haul than a financial-data breach, but security researchers point out that a complete internal staff directory is itself a high-value asset: it hands attackers a ready-made target list for phishing, business email compromise and password-spraying campaigns, without them ever needing to guess at an organization’s structure.
How the Alleged Azure and Entra ID Breach Happened
Every technical writeup of this incident lands on the same root cause: stolen credentials, not a software flaw. Hudson Rock’s analysis, as summarized across multiple outlets, concludes the data was extracted using leaked credentials rather than any vulnerability in Azure or Entra ID itself. The presumed chain of events looks like this: infostealer malware on an employee’s device harvests saved passwords, browser session cookies or authentication tokens tied to Microsoft 365 and Entra ID; the attacker then reuses those valid credentials to sign into the victim’s tenant; once inside, they query the Microsoft Graph API to enumerate users and export directory attributes at scale.
What makes the technique effective is a permissions default many organizations never tighten. In a large share of Entra ID tenants, any authenticated user, not just administrators, can read broad slices of the corporate directory by default. A single compromised low-privilege account is often enough to pull down names, emails and phone numbers for tens or hundreds of thousands of colleagues. That default is a known configuration risk, not a bug, which is why Microsoft has not issued a security advisory or CVE tied to this specific campaign.
The Nine Companies and What Was Allegedly Exposed
The table below compiles the per-company figures attributed to Hudson Rock’s investigation and repeated across BleepingComputer, Help Net Security and regional outlets covering the story.
| Company | Sector | Estimated Records | Public Response as of Aug 29, 2026 |
|---|---|---|---|
| McDonald’s | Fast food / retail | ~1,700,000 | No public statement reported |
| Tata Consultancy Services (TCS) | IT services | ~800,000 | Denied evidence of dark-web leak in stock exchange filing |
| Vodafone | Telecom | ~425,000 | No public statement reported |
| HCL Technologies | IT services | ~250,000 | Denied evidence of dark-web leak in stock exchange filing |
| InterContinental Hotels Group (IHG) | Hospitality | ~185,000 | No public statement reported |
| Kyndryl | IT infrastructure services | ~170,000 | No public statement reported |
| Gap Inc. | Retail | ~80,000 | No public statement reported |
| Hexaware Technologies | IT services | Not disclosed | Denied evidence of dark-web leak in stock exchange filing |
| Wyndham Hotels | Hospitality | Not disclosed | No public statement reported |
Three of the nine named companies, TCS, HCL Technologies and Hexaware Technologies, filed statements with Indian stock exchanges within roughly a week of the story breaking, saying internal investigations found no evidence that employee data had actually surfaced on the dark web The remaining six companies had not issued public confirmations or denials as of the most recent coverage reviewed for this article
Hudson Rock’s Investigation and What It Found
Hudson Rock built its assessment around the internal consistency of the leaked samples rather than direct access to victim networks, a common constraint when researchers evaluate stolen-data listings on criminal marketplaces. The firm’s writeup, titled around the theme of a “massive Azure exfiltration campaign,” frames the incident as part of a broader shift in how enterprise breaches now originate: not through a patched-late server flaw, but through an employee’s personal device getting infected with infostealer malware months or years before the eventual data sale.
According to BleepingComputer’s review of the listings, one of the datasets, the TCS dump, was described by the seller as downloaded directly from an Azure tenant using compromised credentials, a claim consistent with Hudson Rock’s independent read of the file structure. Researchers stress this does not prove every named company’s live tenant remains compromised today. It shows that at some point, valid credentials tied to each organization were used to pull directory data, and that data is now being marketed for resale.
No CVE, No Confirmed Azure Vulnerability
It is worth being precise about what this incident is not. It is not a repeat of a patched Microsoft flaw, and it has not been assigned a CVE identifier. Coverage from technical forums and security outlets is consistent on this point: the available evidence points to credential theft and permissive directory-read configurations, not a defect in Azure or Entra ID code. That framing lines up with Microsoft’s general public messaging in 2026, which has repeatedly emphasized identity compromise, rather than infrastructure exploits, as the dominant vector behind large cloud breaches.
Microsoft’s own security team documented a related dynamic in May 2026, describing how a threat actor it tracks as Storm-2949 turned a single compromised identity into what the company called a cloud-wide breach against a targeted organization, exfiltrating data from high-value assets across that tenant. That case, detailed on the Microsoft Security Blog, was a different campaign against a different target, but it illustrates the same underlying weakness TheHatman’s activity appears to exploit: once an attacker holds one valid identity, the cloud tenant’s own trust model can do the rest of the work.
Identity Theft Has Replaced the Server Exploit as the Default Cloud Attack Path
For most of the last decade, headline breaches followed a familiar arc: a vendor discloses a critical vulnerability, a CVE number gets assigned, a patch ships, and attackers race to exploit whichever organizations move too slowly. VMware’s vCenter zero-day and the string of SonicWall and Cisco firewall flaws disclosed earlier in 2026 all followed that pattern. TheHatman’s Azure campaign follows a different one entirely, and it is becoming the more common one.
Infostealer malware, cheap, widely available on criminal forums, and increasingly effective at harvesting browser-stored credentials and session tokens, has turned individual employee devices into the weak point that matters most. A worker’s personal laptop getting infected has nothing to do with a company’s patch cadence, its firewall rules, or its vulnerability management program. It has everything to do with whether that stolen session can still authenticate to a corporate Entra ID tenant weeks or months later, and whether that tenant restricts what an ordinary authenticated user can read once inside.
Market and Business Impact
None of the nine named companies has disclosed a material financial impact tied specifically to this incident, and the muted market reaction reflects that: this is a directory-data exposure, not a ransomware operational shutdown or a confirmed financial-records theft, so it has not moved the kind of needle that, for example, a production-halting ransomware attack does. But the reputational calculus is different from the financial one. For IT services firms like TCS, HCL Technologies and Kyndryl, whose entire business model rests on client trust in their security posture, being named as a victim in a Fortune 500 breach story, even one still under investigation, carries weight with enterprise clients evaluating vendor risk during procurement cycles.
There is also a downstream cost that rarely makes headlines: every one of the roughly 3.6 million individuals whose names, emails and phone numbers are now circulating on a criminal marketplace becomes a more efficient phishing target. Security teams at all nine companies, and arguably at any organization using Entra ID with loose directory-read defaults, now have to budget for elevated phishing-awareness training and tighter email filtering in the weeks following this kind of disclosure, regardless of whether their own tenant was among those named.
How This Compares to Other 2026 Data Breaches
TheHatman’s 3.6 million records is modest next to the largest breaches disclosed so far in 2026, but the multi-victim, single-campaign structure sets it apart from single-target incidents. The table below places it alongside other major 2026 breach disclosures for scale.
| Incident | Disclosed | Records/Victims Claimed | Reported Cause |
|---|---|---|---|
| McKesson (ShinyHunters) | 2026 | 284,000,000 | Third-party/SaaS data theft |
| Canvas LMS / Instructure | 2026 | 275,000,000 | Data extortion claim |
| Conduent | 2026 | 62,200,000 | Network intrusion |
| Manchester Airport Group | 2026 | 8,700,000 | Data breach, customer records |
| KDDI (six ISPs) | 2026 | 12,200,000 | Network breach |
| TheHatman / Azure Entra ID | Aug 2026 | ~3,600,000 | Compromised credentials, infostealer malware |
What stands out in that comparison is not the record count but the mechanism. Most of the largest 2026 breaches trace back to a single organization’s network or a single third-party vendor’s systems getting compromised. TheHatman’s campaign instead touches nine unrelated enterprises through the same generic technique, credential theft plus permissive Entra ID directory access, applied repeatedly across different targets. That repeatability is what security researchers find more concerning than the raw record count.
What Security Teams Should Check Right Now
Organizations running Microsoft 365 or Azure/Entra ID tenants can take a few concrete steps this week rather than waiting for a formal advisory that, in this case, may never arrive since no vulnerability has been identified. Security teams should audit which directory roles and default user permissions allow broad enumeration of employee data through the Microsoft Graph API, restrict that access to only what business processes require, and enforce phishing-resistant multi-factor authentication across all accounts, not just privileged ones.
Monitoring for anomalous Graph API query volume is another practical control. A single account suddenly issuing thousands of directory read requests in a short window is a strong signal of exactly the kind of bulk export TheHatman’s listings describe, and it is detectable with standard Entra ID sign-in and audit logs if an organization is actually watching for it.
# Example: check Entra ID sign-in logs for unusual Graph API directory read volume
Connect-MgGraph -Scopes "AuditLog.Read.All","Directory.Read.All"
Get-MgAuditLogSignIn -Filter "createdDateTime ge 2026-08-01" |
Where-Object { $_.ResourceDisplayName -eq "Microsoft Graph" } |
Group-Object UserId |
Sort-Object Count -Descending |
Select-Object -First 20 Name, Count
Beyond technical controls, security teams evaluating identity threat detection tooling, an area covered in detail in Tech Insider’s comparison of CrowdStrike, Defender and Silverfort’s ITDR platforms, should treat this incident as a live example of why identity-focused monitoring now sits alongside endpoint and network detection as a baseline requirement, not an optional upgrade.
Corporate Denials and Why Researchers Remain Skeptical
The gap between Hudson Rock’s authenticity assessment and the three companies’ public denials is itself part of the story. TCS, HCL Technologies and Hexaware each told Indian stock exchanges they found no evidence employee data had been leaked on the dark web, filings covered in detail by Moneycontrol. But the same report notes that cyber experts reviewing the same samples were not convinced by those denials, pointing to the consistency of the field structures and domain formatting as evidence the data originated from real Entra ID exports rather than a fabricated or recycled dataset.
This tension is common in early-stage breach disclosures: a company’s internal investigation, often scoped narrowly to confirmed unauthorized access rather than to whether any employee data matches a criminal listing, can technically be accurate while still not resolving the broader question of whether the listed data is genuine. Absent a company publicly reproducing and confirming the exact records in the leaked sample, outside researchers are left assessing authenticity from structural and contextual clues alone.
How Infostealer Malware Became 2026’s Default Breach Vector
Infostealer-driven breaches are not new, but 2026 has seen them scale from isolated account takeovers into full corporate directory exfiltration campaigns like this one. The pattern shows up across unrelated incidents this year, from ransomware groups buying initial access from infostealer log marketplaces to cloud exfiltration campaigns like TheHatman’s that skip the ransomware step entirely and go straight to reselling stolen directory data.
Part of what drives this shift is economics. Building or buying a working zero-day exploit against a hardened enterprise firewall or hypervisor takes real technical skill and, increasingly, real money on exploit-broker markets. Buying a batch of infostealer logs containing valid corporate session tokens costs a fraction of that and requires far less expertise, which is why criminal forums increasingly favor credential-based access over exploit development for exactly this kind of large-scale, low-effort data harvesting.
What Happens Next: Five Predictions
- More named victims are likely to surface as researchers and journalists continue combing through the full dataset TheHatman is advertising, given that nine companies were identified from what appears to be a larger campaign.
- Expect at least one of the nine companies to eventually confirm unauthorized access in a formal breach notification, even if early stock-exchange filings characterized findings as inconclusive.
- Microsoft is likely to face renewed pressure to tighten default Entra ID directory-read permissions for standard authenticated users, following the same trajectory as past defaults that were quietly hardened after high-profile abuse cases.
- Identity threat detection and response tooling adoption will accelerate among enterprises running large Microsoft 365 and Azure estates, as this incident becomes a reference case in vendor sales conversations throughout the rest of 2026.
- Expect follow-on phishing and business email compromise campaigns targeting employees at the nine named companies over the coming months, using the exposed directory data to craft more convincing lures than generic spam.
Broader Context: Cloud Identity Is the New Perimeter
A decade ago, “perimeter security” meant firewalls, VPN gateways and patched web servers. In 2026, for organizations that have moved most of their infrastructure into Microsoft 365, Azure and Entra ID, the real perimeter is the set of valid credentials that can authenticate into those environments. TheHatman’s campaign is a data point in a trend security researchers have been describing all year: attackers no longer need to breach a network boundary when they can buy or steal a working login instead.
That shift has practical implications for how enterprises allocate security budgets. Vulnerability management programs, firewall hardening and patch cadence remain necessary, covered in Tech Insider’s guide to building a vulnerability management program, but they do not address credential theft happening on an employee’s personal device, far outside any corporate patch cycle. Closing that gap increasingly requires identity-centric controls: conditional access policies, continuous session risk scoring and tighter default permissions inside the cloud tenant itself, an area also addressed in Tech Insider’s Microsoft Defender for Cloud setup guide.
How TheHatman Incident Fits Into 2026’s Breach Volume
Data breach volume across 2026 has already run well ahead of prior years, with cumulative victim counts across publicly reported incidents surpassing 471 million in just the first half of the year, a figure detailed in Tech Insider’s first-half 2026 data breach roundup. TheHatman’s alleged 3.6 million Azure records add to that running total, but the more useful signal is what mechanism keeps recurring across these incidents. Breaches like the Manchester Airport Group’s 8.7 million-record disclosure and the ShinyHunters-linked McKesson breach affecting 284 million records each trace back to different specific failures, but all sit inside the same broader 2026 pattern of attackers favoring stolen access and third-party exposure over custom-built exploits.
What This Means for Enterprise Microsoft 365 Customers
For the millions of organizations running Microsoft 365 and Azure, the practical takeaway is not that Azure is inherently insecure, no vulnerability has been found in the platform itself, but that identity hygiene now determines breach exposure more than infrastructure hardening does. Enterprises should treat this incident as a prompt to audit directory-read defaults, review conditional access policies, and confirm that MFA enforcement has no exceptions for legacy authentication protocols that infostealer-harvested credentials can often still bypass.
Frequently Asked Questions
What is the TheHatman Azure data breach?
It refers to a cybercriminal alias, “TheHatman,” advertising roughly 3.6 million employee-directory records allegedly exfiltrated from the Microsoft Azure and Entra ID tenants of nine companies, according to cybercrime intelligence firm Hudson Rock and reporting from BleepingComputer and Help Net Security in August 2026.
Which companies are named in the breach claims?
McDonald’s, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels are the nine organizations named in the reporting reviewed for this article.
Was this caused by a Microsoft Azure vulnerability?
No CVE or confirmed platform vulnerability has been tied to this incident. Researchers attribute the data theft to compromised employee credentials, likely harvested by infostealer malware, rather than to any flaw in Azure or Entra ID.
Have any of the companies confirmed the breach?
TCS, HCL Technologies and Hexaware Technologies each filed statements with Indian stock exchanges saying internal investigations found no evidence of a dark-web leak The other six named companies had not issued public confirmations or denials as of the latest reporting
What kind of data was allegedly exposed?
Reports describe employee names, corporate email addresses, internal employee IDs, phone numbers and, in some tenants, physical addresses, drawn from internal Entra ID directory exports rather than financial or customer records.
How does this compare to other 2026 breaches?
At roughly 3.6 million records, it is smaller in scale than the year’s largest disclosures, such as the 284-million-record McKesson breach or the 275-million-record Canvas LMS incident, but it is notable for touching nine unrelated companies through the same credential-theft technique in a single campaign.
What should organizations using Microsoft 365 or Azure do now?
Security teams should audit and restrict default directory-read permissions in Entra ID, enforce phishing-resistant multi-factor authentication across all accounts, and monitor for unusual bulk Microsoft Graph API query activity that could indicate a similar directory export attempt.
Is this related to the Storm-2949 campaign Microsoft disclosed earlier in 2026?
They are separate incidents against different targets, but both illustrate the same underlying weakness: a single compromised identity can be leveraged to access and exfiltrate large volumes of data across a Microsoft cloud tenant once an attacker is authenticated.
![TheHatman Hits 3.6M Records [2026] TheHatman Hits 3.6M Records [2026]](https://tech-insider.org/wp-content/uploads/2026/08/thehatman-azure-entra-breach-3-6-million-2026-1.webp)