TheHatman Claims Azure Tenant Data Theft from Major Enterprises
What Is It?
A threat actor using the name TheHatman is reportedly selling millions of employee-directory records allegedly taken from the Microsoft Azure and Entra tenants of several major organizations.
The named companies include McDonald’s Corporation, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap Inc., Hexaware Technologies and Wyndham Hotels.
According to Hudson Rock, the largest advertised dataset contains more than 1.7 million alleged McDonald’s records. The actor also claims to possess approximately 800,000 TCS records and 425,000 Vodafone records.
Samples reviewed by researchers appear credible based on corporate email domains and fields consistent with Azure directory exports. However, the affected organizations have not publicly confirmed the reported breaches, and the age, completeness and total size of the datasets remain unverified.
The actor claims the information was accessed using compromised credentials. Current reporting points toward credential theft—not a vulnerability in Microsoft Azure itself.
Why Should You Care?
The allegedly exposed information includes employee names, corporate email addresses, phone numbers, employee IDs, job titles, reporting relationships, group memberships and the names of service or privileged accounts.
Even without passwords, this information can give attackers a detailed map of an organization. They can identify executives, finance employees, IT administrators and other high-value targets, then create convincing spear-phishing or business email compromise attacks.
If valid credentials were used to access the tenants, the incident also demonstrates how a single compromised identity can expose information across a much larger cloud environment.
What Businesses Should Do
- Review Microsoft Entra sign-in and audit logs for unfamiliar locations, devices or unusual activity.
- Investigate risky users and leaked-credential alerts promptly.
- Reset credentials and revoke active sessions for suspected compromised accounts.
- Require multi-factor authentication and consider phishing-resistant methods for administrators.
- Limit privileged access and review Global Administrator, service and inactive accounts.
- Protect endpoints against infostealer malware with patching, endpoint detection and application controls.
- Train employees to recognize phishing messages that use real names, roles and reporting relationships.
- Review exposed service accounts and rotate any credentials or secrets believed to be compromised.
Microsoft provides guidance for investigating risky identities, revoking user access and requiring phishing-resistant MFA.
Final Thoughts
This incident remains based on a threat actor’s claims and researcher analysis, but the lesson is clear: cloud security depends heavily on identity security.
Organizations should assume that employee and administrator information can be used to make phishing attempts more believable. Strong authentication, endpoint protection, access controls and active monitoring help reduce the chance that one stolen credential becomes a much larger incident.
Britec helps businesses strengthen Microsoft 365 security, protect endpoints and monitor the technology their teams depend on. Talk to a Britec expert about improving your organization’s identity and cloud security.