A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.
Starting July 31st, multiple posts from someone using the alias “TheHatman” advertised data dumps from major organizations, including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl.
In total, the threat actor claims to have 3.64 million data records, with the most recent breach posted on Sunday, containing an alleged 1.7 million employee records from McDonalds.
“I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” the threat actor says in the post.
TheHatman says that the information includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records.
Advertisement
Cybercriminal advertising McDonald’s database with employee records source: BleepingComputer
The second-largest data dump advertised is allegedly stolen from Tata Consultancy: an Azure dump with more than 800,000 employee records “downloaded directly from Azure Tenant using compromised credentials,” the cybercriminal states.
However, in a notification to the National Stock Exchange of India, Tata says it investigated the alleged breach and found no “credible evidence of a breach of TCS systems or customer environments.”
The company states that the details appear to be at least four years old and include only basic employee information.
“The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years,” Tata says.
The company also added that it reviewed its defenses and found that they remain effective.
Advertisement
In a statement for BleepingComputer, a Gap Inc. spokesperson said that the company found no evidence of a breach. Additionally, the advertised data is not sensitive in nature and “dated back to several years ago.”
“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” the Gap Inc. representative said.
Between July 31st and August 16, TheHatman has offered to sell data dumps for the following organizations:
Company
Advertisement
Size
Type
Data type
McDonalds
1.7+ million records
Advertisement
Azure Internal Employee Dump
Full Name, Email, Title, Phone, Address
Gap Inc.
80,000+ records
Azure Internal Employee Dump
Advertisement
Full Name, Email, Title, Phone, Address
Vodafone
425,000+ records
Azure Internal Employee Dump
Full Name, Email, Title, Phone, Address
TCS (Tata Consultancy)
Advertisement
800,000+ records
Azure dump
Full Name, Email, Title, Phone, Address
HCL Technologies
250,000+ records
Advertisement
Azure dump
Full Name, Email, Title, Phone, Address
InterContinental Hotels
185,000+ records
Azure dump
Advertisement
Full Name, Email, Title, Phone, Address
Wyndham Hotels
9,000+ records
Azure/Entra dump
Full Name, Email, Title, Phone, Address
Hexaware
Advertisement
20,000+ records
Azure/Entra dump
Full Name, Email, Employee ID, Phone, Address
Kyndryl.com
170,000+ records
Advertisement
Azure/Entra dump
Employee accounts, service accounts, and other tenant account records.
For each advertised database, TheHatman also provided a sample database for potential buyers to verify the data.
Cybercrime intelligence company Hudson Rock analyzed the leaks and confirmed that they contain “foundational corporate directory attributes” and a clear data structure with fields that include “active domains and tenant-specific .onmicrosoft.com structures.”
Advertisement
According to the cybersecurity firm, the dumps also contain service accounts and the names of global administrators, which could facilitate social engineering and spearphishing attacks.
While Hudson Rock has high confidence that the data is authentic, the access vector and exfiltration method remain unknown. BleepingComputer has not been able to independently verify that the data is authentic.
BleepingComputer contacted the listed companies about the potential breach but had not received comments by the time of publication.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
You must be logged in to post a comment Login