The Hatman Stole 3.6 Million Records From 9 Fortune 500 Companies — and Never Touched a Vulnerability

Key Takeaway

  • 🔢 Scale: A threat actor called TheHatman is selling 3.6 million+ employee records stolen from 9 Fortune 500 companies including McDonald’s (1.7M), TCS (800K), Vodafone (425K), HCL Technologies (250K), and IHG (185K)
  • 🔓 Not a Hack: The data was exfiltrated from Azure/Entra tenants using compromised credentials — not a vulnerability in Azure itself, but a credential hygiene failure enabled by infostealer malware
  • ⚠️ What Was Stolen: Full names, corporate emails, phone numbers, physical addresses, job titles, manager details, service accounts, and Global Administrator listings — a roadmap for spear-phishing and privilege escalation
  • 🏢 Industries Hit: IT services, hospitality, telecommunications, retail, and logistics — McDonald’s, Vodafone, TCS, IHG, Kyndryl, Gap Inc., Hexaware, Wyndham Hotels
  • ⚡ What You Should Do: Enforce multi-factor authentication on all Azure/Entra accounts, audit for infostealer infections, and review service account permissions — stolen credentials are the #1 cloud attack vector in 2026

Before you assume your company’s cloud data is safe because you use Microsoft Azure, consider this: a threat actor operating under the alias “TheHatman” just exfiltrated 3.6 million employee records from 9 Fortune 500 companies — and never touched a single vulnerability. The Azure data theft campaign, first reported by Hudson Rock on August 16, 2026, and confirmed by SecurityWeek and Cyber Security News, did not exploit a flaw in Azure. It used compromised credentials harvested by infostealer malware to walk straight through the front door of each organization’s Azure/Entra tenant and download the entire employee directory.

The largest victim is McDonald’s Corporation, with over 1.7 million records stolen, followed by Tata Consultancy Services (TCS) at 800,000, Vodafone at 425,000, HCL Technologies at 250,000, and InterContinental Hotels Group at 185,000. The full victim list includes Kyndryl (170,000), Gap Inc. (80,000), Hexaware Technologies (20,000), and Wyndham Hotels (9,000). TheHatman has been selling these datasets on underground forums for the past week, and Hudson Rock researchers who reviewed sample data say it appears “highly legitimate” based on corporate email domains and field structures that match standard Azure directory exports.

How the Azure Data Theft Happened — Compromised Credentials, Not a Vulnerability

The most important fact about this Azure data theft campaign is what it is not. It is not a vulnerability in Microsoft Azure. It is not a zero-day exploit. It is not a sophisticated nation-state attack. It is a credential hygiene failure at enterprise scale.

According to Hudson Rock’s analysis, the threat actor claims the data was “downloaded using compromised credentials.” Hudson Rock researchers identified compromised Azure credentials originating from infostealer infections linked to most of the affected companies, including machines traced to employees at TCS, Gap Inc., HCL Technologies, and Kyndryl. One compromised device reportedly contained dozens of corporate credentials and hundreds of sensitive session cookies, including direct access to a Kyndryl Azure Active Directory account.

Infostealer malware — malicious software designed to steal passwords, session tokens, and cookies from infected devices — has become the single most important entry vector for cloud data breaches in 2026. An employee downloads what looks like a legitimate file, the infostealer silently harvests their Azure login credentials and session cookies, and the attacker uses those credentials to access the organization’s Azure/Entra portal as if they were the employee. No vulnerability needed. No exploit required. Just stolen passwords and insufficient multi-factor authentication.

What Was Stolen in the Azure Data Theft — A Blueprint for Targeted Attacks

The exfiltrated data goes far beyond basic contact information. According to SecurityWeek, the leaked datasets consistently include:

  • Core identity data: Full names, corporate email addresses (including tenant-specific .onmicrosoft.com structures), phone numbers, and physical addresses
  • Organizational structure: Employee IDs, job titles, departments, manager details, and direct reports — the full reporting hierarchy
  • Access and group mappings: User group memberships, service account details, and Global Administrator account listings

The exposure of service accounts and Global Administrator names is the most dangerous element. Hudson Rock noted that this data “provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations.” An attacker who knows the name and email of a Global Administrator can craft a highly targeted spear-phishing email that impersonates an internal IT department — and because the attacker has the full organizational structure, they know exactly who reports to whom and can impersonate a manager to trick a direct report into approving a fraudulent transfer or surrendering an MFA code.

This is not theoretical. Cyber Security News noted that threat actors routinely weaponize structured directory data like this to run business email compromise (BEC) campaigns, using accurate reporting lines and job titles to impersonate managers or IT staff. The Azure data theft is not just a data breach — it is an ammunition factory for future attacks.

The Azure Data Theft Victim List — 9 Companies, 5 Industries

CompanyIndustryRecords Stolen
McDonald’s CorporationFood & Retail1,700,000+
Tata Consultancy Services (TCS)IT Services800,000+
VodafoneTelecommunications425,000+
HCL TechnologiesIT Services250,000+
InterContinental Hotels Group (IHG)Hospitality185,000+
KyndrylIT Services170,000+
Gap Inc.Retail80,000+
Hexaware TechnologiesIT Services20,000+
Wyndham HotelsHospitality9,000+

The victim selection is notable. These are not small businesses with weak security — they are multinational corporations with dedicated security teams and significant cybersecurity budgets. The fact that TheHatman targeted only massive multinational firms, rather than a broad cross-section of smaller businesses, suggests a deliberate, targeted operation. The attacker knew what they were looking for and where to find it.

Why MFA Was Not Enough — The Infostealer Problem

Many of the affected organizations likely had multi-factor authentication enabled on their Azure accounts. So how did the attacker get in? The answer lies in how infostealer malware works in 2026.

Modern infostealers do not just steal passwords. They steal session tokens and cookies — the digital keys that keep a user logged in after they have already completed MFA. When an employee authenticates to Azure with their password and MFA code, Azure issues a session token that says “this user is authenticated.” If an infostealer steals that session token from the employee’s browser or device, the attacker can use it to access Azure without needing the password or the MFA code. The authentication has already happened. The attacker is simply reusing the result.

This is why the Azure data theft campaign is so significant. It demonstrates that MFA alone is no longer sufficient when the threat actor can steal the session token that MFA produces. The defense is not stronger MFA — it is detecting and remediating infostealer infections before the stolen credentials are used. Endpoint detection and response (EDR), browser security extensions that detect cookie theft, and continuous monitoring for anomalous Azure logins from unfamiliar locations are now essential layers.

What the Azure Data Theft Means for Every Organization Using Azure

The Azure data theft campaign is a wake-up call for every organization that uses Microsoft Azure, Entra ID, or any cloud identity platform — and it echoes the credential hygiene failures we documented in the Gunra ransomware alert, Entra ID, or any cloud identity platform. The lesson is not that Azure is insecure — it is that the credentials used to access Azure are the weakest link, and attackers are exploiting that link at scale.

Three actions are urgent for any organization using Azure or similar cloud platforms:

First, audit for infostealer infections. Hudson Rock and other cybersecurity firms offer tools that scan infostealer logs to identify whether your organization’s credentials have been compromised. If your employees’ credentials are in an infostealer database, attackers already have them — the question is whether they have used them yet.

Second, enforce conditional access policies. Azure Entra ID supports conditional access policies that block logins from unfamiliar locations, require MFA for privileged accounts, and detect impossible travel (a login from New York and a login from Tokyo 10 minutes later). These policies would have blocked many of the credential-based accesses in this campaign.

Third, review service account permissions. The data stolen in this campaign includes service account names and Global Administrator listings. If your service accounts have broader permissions than they need, a compromised credential for one service account can cascade into access to your entire Azure tenant. Apply the principle of least privilege to every account, especially service accounts that often have standing permissions nobody reviews.

The Bigger Picture — Credential Theft Is the New Breach Vector

The Azure data theft campaign arrives in the same week as two other major cybersecurity stories we covered: the SAP Commerce Cloud CVSS 10.0 vulnerability exploited within 72 hours of patch release, and the macOS Screen Sharing flaw exploited for Monero mining. Together, these three incidents paint a picture of the 2026 threat landscape: attackers are moving faster than defenders, whether through rapid vulnerability exploitation or through stolen credentials that bypass vulnerabilities entirely.

The Azure data theft campaign is the most insidious of the three because it requires no vulnerability at all. The SAP and macOS attacks exploited specific flaws that could be patched. The Azure data theft exploited human behavior — employees clicking on malicious files, organizations not enforcing strict enough access policies, and the assumption that MFA alone is sufficient protection. As we noted in our coverage of AI-powered cyberattacks, the gap between attacker speed and defender response is widening. Credential theft closes that gap to zero — the attacker is already inside.

For organizations that have not yet checked whether their Azure credentials appear in infostealer logs, the Azure data theft campaign is a reminder that the question is not whether your credentials have been compromised. The question is whether you know about it yet.

Frequently Asked Questions About the Azure Data Theft Campaign

What is the Azure data theft campaign?

A threat actor called TheHatman is selling 3.6 million+ employee records stolen from 9 Fortune 500 companies — including McDonald’s, TCS, Vodafone, and IHG — on underground forums. The data was exfiltrated from the organizations’ Azure/Entra tenants using compromised credentials harvested by infostealer malware, not by exploiting a vulnerability in Azure itself.

Was Microsoft Azure hacked?

No. This is not a vulnerability in Microsoft Azure. The attacker used compromised credentials — stolen passwords and session tokens harvested by infostealer malware from employee devices — to access the organizations’ Azure tenants as if they were legitimate users. The failure was in credential hygiene, not in the Azure platform.

Which companies were affected by the Azure data theft?

McDonald’s Corporation (1.7M records), Tata Consultancy Services (800K), Vodafone (425K), HCL Technologies (250K), InterContinental Hotels Group (185K), Kyndryl (170K), Gap Inc. (80K), Hexaware Technologies (20K), and Wyndham Hotels (9K). The victims span IT services, hospitality, telecommunications, retail, and logistics.

What data was stolen in the Azure data theft?

Employee directories including full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, manager details, direct reports, user group memberships, service account details, and Global Administrator account listings. This data enables targeted spear-phishing, business email compromise, and privilege escalation attacks.

How can organizations protect against Azure data theft?

Organizations should audit for infostealer infections using services that scan stolen credential databases, enforce conditional access policies in Azure Entra ID (block unfamiliar locations, require MFA for privileged accounts, detect impossible travel), and review service account permissions to apply least privilege. MFA alone is not sufficient because modern infostealers steal session tokens that bypass MFA.

What is infostealer malware?

Infostealer malware is malicious software that steals passwords, session tokens, and cookies from infected devices. When an employee’s device is infected, the attacker can harvest their Azure login credentials and session tokens — including tokens generated after MFA — and use them to access the organization’s cloud services without needing the password or MFA code.

Who is TheHatman?

TheHatman is the alias used by the threat actor selling the stolen Azure data on underground forums. The identity is unknown. The targeted nature of the campaign — only Fortune 500 companies, across multiple industries — suggests a deliberate and sophisticated operation rather than opportunistic scanning.

Cybersecurity Disclosure: This article is for informational purposes only and does not constitute professional cybersecurity advice. Organizations should consult with qualified security professionals and follow vendor-specific guidance when implementing security controls. WorldNgayon.com is not liable for any actions taken based on the information presented here.

Editorial Transparency Note:This article was researched and drafted with AI assistance, then reviewed, verified, and approved by Edmon Agron. All sources have been cross-checked against original publications as of the date of publication.

Leave a Reply