A cybercriminal using the alias “TheHatman” is advertising millions of employee records allegedly obtained from the Microsoft Azure environments of several major international companies. The seller claims compromised credentials provided access to corporate tenants belonging to organizations including McDonald’s, Vodafone, Tata Consultancy Services (TCS), Gap Inc., HCL Technologies, InterContinental Hotels Group, Wyndham Hotels, Hexaware, and Kyndryl.

 

 

The listings began appearing on July 31 and continued through August 16. Together, the datasets are claimed to contain approximately 3.64 million records. The largest individual listing appeared on Sunday and allegedly contains more than 1.7 million records associated with McDonald’s employees. According to the seller, the information was downloaded directly from the company’s Azure tenant using compromised credentials. The alleged McDonald’s dataset contains names, employee IDs, email addresses, job titles, telephone numbers, postal addresses, and other account information.

Another large dataset advertised by TheHatman allegedly contains more than 800,000 TCS employee records. The seller again described the information as an Azure dump obtained through compromised credentials, but TCS investigated the allegation and disputed that its systems had been breached.

In a regulatory filing, TCS said it found no credible evidence that either its own infrastructure or customer environments had been compromised. The company determined that the information associated with the claim appeared to be at least four years old and consisted only of basic employee details. TCS also addressed the attacker’s claim that password spraying and multi-factor authentication fatigue had been used, saying protections against those techniques had been in place for more than two years.

Gap Inc. similarly found no indication that its corporate infrastructure had been compromised. The company reported that its preliminary investigation found the advertised information to be limited, non-sensitive, and several years old. TheHatman’s listing claims the Gap dataset contains more than 80,000 records.

Other advertised datasets include more than 425,000 records attributed to Vodafone, 250,000 associated with HCL Technologies, 185,000 linked to InterContinental Hotels, and 170,000 connected to Kyndryl. Smaller collections were attributed to Hexaware and Wyndham Hotels. The seller provided samples alongside the listings so potential buyers could examine portions of the purported information.

Cybercrime intelligence company Hudson Rock examined the leaked material and reported finding corporate directory information with structured fields, active domains, and tenant-specific Microsoft “.onmicrosoft.com” references. The researchers also identified service accounts and names associated with global administrator roles.

Hudson Rock said it has high confidence that the datasets themselves are authentic. However, that assessment does not establish how the information was originally obtained. The researchers could not confirm the seller’s description of the initial access or the method allegedly used to extract the information from Azure environments.

That distinction is particularly important because responses from TCS and Gap challenge the suggestion that their current corporate environments were successfully breached. At this stage, the available evidence does not independently confirm that every dataset advertised by TheHatman was recently extracted directly from the companies’ Azure tenants.

The listings therefore represent a mixture of attacker claims, analysis of the advertised data, and corporate investigations that have produced conflicting conclusions about its origin. While millions of records are being offered for sale, the precise source, age, and acquisition method of the information remain unresolved.

Leave a Reply