Skip to content
Data breachOngoing

Fortune 500 Azure/Entra ID data theft (TheHatman)

A threat actor using the handle TheHatman advertised roughly 3.64 million employee directory records scraped from the Microsoft Azure and Entra ID tenants of multiple Fortune 500 companies, with access reportedly gained through stolen credentials harvested by infostealer malware.

Victim
Multiple Fortune 500 companies (Azure/Entra ID tenants)
records
3.6M

Beginning 31 July 2026 and drawing wide reporting by 18 August 2026, a threat actor using the handle TheHatman advertised a growing set of corporate employee directories on a criminal forum, reaching a running total of roughly 3.64 million records drawn from the Microsoft Azure and Entra ID tenants of multiple Fortune 500 companies. Named victims in reporting included McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Kyndryl, Hexaware and Wyndham.

There was no exotic exploit involved. As one analysis put it, "TheHatman logged in" โ€” the access was reportedly obtained using stolen credentials, with strong evidence pointing to infostealer malware harvesting logins, aided by phishing and gaps in multi-factor authentication enforcement. Once inside a tenant, the actor exported directory data available to an authenticated account.

What happened

The single largest dump was attributed to McDonald's, at roughly 1.7 million employee records โ€” a figure reflecting the company's enormous global and franchise workforce rather than any particular weakness. Across the affected tenants, the exposed data included names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts and other tenant-related account information.

Because the data was directory information rather than, for example, financial or health records, the immediate harm centered on enterprise-targeted phishing and business-email-compromise rather than direct identity theft. But a validated map of a company's staff โ€” names, roles, reporting structure and service accounts โ€” is precisely the reconnaissance attackers need to craft convincing internal lures and to identify privileged accounts for follow-on intrusion.

Impact

  • Roughly 3.64 million employee directory records across multiple Fortune 500 Azure/Entra ID tenants were offered for sale.
  • Exposed fields included names, employee IDs, emails, job titles, phone numbers, addresses and service-account details.
  • The largest single set, about 1.7 million records, was attributed to McDonald's; affected organizations faced elevated phishing and BEC risk and follow-on intrusion potential.

Why it matters

The TheHatman campaign underscores a shift in how large enterprises are breached: not through a headline vulnerability but through valid credentials stolen by infostealers and reused against cloud-identity tenants that lack universally enforced, phishing-resistant MFA. Directory exports may look low-severity next to a ransomware dump, but they are premium raw material for the next attack โ€” turning one tenant's staff list into a targeting database for social engineering across the organization and its suppliers. The incident is a reminder that identity is the perimeter, and that infostealer hygiene and MFA coverage are now core breach-prevention controls.

Timeline

  1. TheHatman begins posting corporate employee directories to a criminal forum.

  2. The running total reaches roughly 3.64 million records; security researchers and vendors report the campaign publicly.

Sources

  1. helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/08/18/azure-data-leak-fortune-500-companies/
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
  3. securityweek.comhttps://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/

Related incidents