I'm LongbridgeAI, I can summarize articles.A cybercriminal known as TheHatman is selling stolen employee directory data from major corporations, including McDonald's, Vodafone, and Tata Consultancy Services, via compromised Microsoft Azure credentials. Over 1.7 million records were exposed at McDonald's alone. The leaked data contains sensitive hierarchical information and Global Administrator listings, posing significant risks for spear-phishing and privilege escalation attacks.
A threat actor operating on underground forums has been systematically selling internal employee directory data allegedly stolen from some of the world's largest corporations through compromised Microsoft Azure and Entra credentials. The campaign — attributed to a seller known as TheHatman — has surfaced data from at least nine Fortune 500-level enterprises over the past week, with McDonald's alone accounting for more than 1.7 million exposed records. Security researchers who reviewed sample datasets say the information appears highly credible.
Key Points
- TheHatman has listed stolen Azure directory data from at least nine major corporations on underground forums over the past week
- McDonald's leads with over 1.7 million exposed records, followed by Tata Consultancy Services at 800,000, Vodafone at 425,000 and HCL Technologies at 250,000
- Additional victims include InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels
- Hudson Rock researchers say the datasets appear highly credible based on corporate email domain structures and field formatting consistent with Azure directory exports
- Exposed data includes Global Administrator account listings — providing attackers with a targeting map for privilege escalation, spear-phishing and ransomware deployment
- Hudson Rock identified infostealer-compromised Azure credentials linked to most affected companies, supporting the theory that session token theft was the primary entry vector

What Was Stolen and From Whom
The scale of the campaign is significant both in the volume of records and in the profile of the organisations affected. TheHatman has flooded underground forums with listings spanning IT services, hospitality, telecommunications, retail and logistics — a cross-sector spread that suggests either broad credential harvesting or targeted exploitation of a common vulnerability in how large enterprises manage Azure tenant access.
McDonald's Corporation tops the list at more than 1.7 million exposed records. Tata Consultancy Services follows at approximately 800,000, Vodafone at around 425,000 and HCL Technologies at roughly 250,000. InterContinental Hotels Group has approximately 185,000 records listed, Kyndryl 170,000, Gap Inc. 80,000, Hexaware Technologies 20,000 and Wyndham Hotels approximately 9,000.
Hudson Rock researchers reviewed sample datasets and said the information appears highly credible. Corporate email domains and field structures align precisely with standard Azure directory exports — the kind of formatting consistency that distinguishes genuine enterprise data from fabricated or aggregated datasets.
What the Data Contains
The leaked datasets follow a consistent template across all listed organisations. Core fields include full names, corporate email addresses drawn from both active company domains and tenant-specific onmicrosoft.com structures, phone numbers and physical addresses.
Beyond basic contact details, the dumps expose organisational data including employee IDs, job titles, department assignments, manager relationships and direct reports — information that provides a complete hierarchical map of an organisation's personnel structure.
The most alarming element of the exposed data is the inclusion of access and group mapping information. Service account details are present across multiple listings, and in some cases the data includes listings of Global Administrator accounts — the highest-privilege accounts within an Azure tenant. Exposing that information hands attackers a ready-made blueprint for targeted spear-phishing campaigns impersonating senior IT staff, social engineering operations exploiting accurate reporting line data and privilege escalation attacks that use administrator account identities as their starting point.

How the Intrusions Likely Occurred
TheHatman has consistently claimed the data was obtained using compromised credentials, but the precise entry point for each organisation remains unconfirmed. Hudson Rock's analysis points toward several plausible mechanisms.
Infostealer malware harvesting session tokens directly from employee machines is the most strongly supported theory. Hudson Rock researchers identified compromised Azure credentials tied to infostealer infections linked to most of the affected companies — including machines traced to employees at TCS, Gap Inc., HCL Technologies and Kyndryl. One compromised device reportedly contained dozens of corporate credentials and hundreds of sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account.
Other possible vectors include phishing campaigns that yielded administrative-level credentials, tenants operating without strict multi-factor authentication enforcement, or abuse of third-party API integrations with overly broad read permissions on directory data. The speed and consistency of the data dumps — covering multiple large organisations in a short timeframe with uniform formatting — points to a systematic, likely automated, extraction process once initial footholds were established.
The fact that only massive multinational enterprises appear in the campaign, rather than a cross-section of smaller businesses, suggests deliberate targeting based on harvested credentials rather than exploitation of an underlying Azure platform vulnerability that would affect organisations indiscriminately.

The Real-World Risk
The immediate risk from the leaked data is not simply that employee contact information is now on underground forums. The structured nature of the data — with accurate reporting lines, job titles, department hierarchies and service account details — makes it directly weaponisable for sophisticated follow-on attacks.
Business email compromise operations built on accurate organisational data are significantly more convincing than generic phishing attempts. A threat actor who knows that a specific employee reports to a specific manager in a specific department can craft an impersonation that is difficult to distinguish from legitimate internal communication. Approval for fraudulent financial transfers, surrender of MFA codes and access to sensitive systems have all been achieved through BEC attacks built on precisely this kind of directory intelligence.
The exposure of service account details and Global Administrator account names provides initial access brokers and ransomware operators with a targeting map — a prioritised list of the accounts most likely to provide the fastest route into critical infrastructure. Organisations where those accounts have been exposed should treat them as compromised until confirmed otherwise.
What Organisations Should Do
The campaign is a reminder that credential hygiene — not perimeter defence — now determines the primary exposure surface for enterprise Azure environments. Several specific measures address the attack vectors most likely to have been exploited.
Continuous monitoring for infostealer-compromised credentials is essential. Session tokens harvested from employee devices can provide access to Azure tenants without triggering authentication alerts, making traditional login monitoring insufficient. Services that track credential exposure across underground markets and infostealer logs provide early warning before stolen credentials are weaponised.
Multi-factor authentication should be enforced across all tenant portals without exception. Tenants that permit access without MFA on any pathway — including legacy authentication protocols — provide the bypass route that makes credential theft immediately actionable. Third-party API integrations with read access to directory data should be audited for permission scope, with access reduced to the minimum required for the integration's stated purpose.
Organisations that appear in the listed data should treat the exposed employee records as a spear-phishing resource now available to sophisticated threat actors, and should brief relevant staff — particularly those in finance, IT and executive functions — on the increased risk of convincing impersonation attempts.
Sources
Hudson Rock threat intelligence analysis of TheHatman Azure directory data campaign, August 2026. Cybersecurity News reporting on Azure credential theft campaign, August 2026. Sample dataset review by Hudson Rock researchers confirming field structure credibility, 2026. Infostealer credential compromise evidence linked to TCS, Gap Inc., HCL Technologies and Kyndryl, per Hudson Rock analysis, 2026.
