
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.
Since July 31, multiple posts by someone using the pseudonym “TheHatman” have advertised data dumps from major organizations, including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG) and Kyndryl.
In total, the threat claimed to have 3.64 million data records, with the latest breach published on Sunday containing an alleged 1.7 million records of McDonalds employees.
“I am selling an internal dump of McDonald’s Corporation employees downloaded directly from Azure Tenant using compromised credentials,” the threat actor says in the post.
TheHatman says the information includes names, employee IDs, email addresses, job titles, phone numbers, mailing addresses, service accounts and other tenant account records.

source: BleepingComputer
The second largest advertised data dump was allegedly stolen from Tata Consultancy: an Azure dump with more than 800,000 employee records “downloaded directly from the Azure Tenant using compromised credentials,” the cybercriminal stated.
However, in a notification to the National Stock Exchange of India, Tata said it investigated the alleged breach and found “no credible evidence of a breach of TCS systems or the customer environment”.
The company says the details appear to be at least four years old and include only basic employee information.
“The attacker claimed to have used password spray and multi-factor authentication (MFA) fatigue as an attack vector. The company has had strong safeguards against such techniques for over two years,” Dad says.
The company also added that it had reviewed its defenses and found that they remained effective.
In a statement to BleepingComputer, a spokesperson for Gap Inc. said the company had found no evidence of wrongdoing. Furthermore, the advertised data is not sensitive in nature and “dates back several years”.
“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated several years ago. Of note, there is no evidence to suggest that our corporate systems were compromised,” said the Gap Inc. representative.
Between July 31 and August 16, TheHatman offered to sell data dumps to the following organizations:
| Company | Size | Type | Data type |
| McDonald’s | 1.7+ million records | Azure employee attrition internally | Full name, email, title, phone, address |
| Gap Inc. | 80,000+ records | Azure employee attrition internally | Full name, email, title, phone, address |
| Vodafone | 425,000+ records | Azure employee attrition internally | Full name, email, title, phone, address |
| TCS (Tata Consultancy) | 800,000+ records | Azure dump | Full name, email, title, phone, address |
| HCL Technologies | 250,000+ records | Azure dump | Full name, email, title, phone, address |
| InterContinental Hotels | 185,000+ records | Azure dump | Full name, email, title, phone, address |
| Wyndham Hotels | 9000+ records | Azure/Entra dump | Full name, email, title, phone, address |
| Hexaware | 20,000+ records | Azure/Entra dump | Full Name, Email, Employee ID, Phone, Address |
| Kyndryl.com | 170,000+ records | Azure/Entra dump | Employee accounts, service accounts and other tenant account records. |
For each advertised database, TheHatman also provided a sample database for potential buyers to check out.
Cyber crime intelligence company Hudson Rock analyzed the leaks and confirmed that they contain “root enterprise directory attributes” and a clear data structure with fields that include “active domains and client-specific .onmicrosoft.com structures.”
According to the cybersecurity firm, the dumps also contain service accounts and global administrator names, which could facilitate social engineering and phishing attacks.
While Hudson Rock has high confidence that the data is authentic, the access vector and exfiltration method remain unknown. BleepingComputer has not been able to independently verify that the data is authentic.
BleepingComputer contacted the companies listed about the potential breach, but did not receive comment by the time of publication.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

