Microsoft Azure Directory Leak Exposes Global Corporations
A Massive Dark Web Data Sale
Threat actors recently listed 3.64 million corporate records for sale on the dark web. A seller known as “TheHatman” claims these databases originate from Microsoft Azure and Entra directories. Consequently, this exposure impacts nine major corporations globally. These victims include prominent entities like McDonald’s, Vodafone, Tata Consultancy Services, and HCL Technologies. The illicit listings contain employee names, job titles, and business phone numbers. Furthermore, they reveal departmental information, manager details, and technical account credentials. Attackers highly prize the inclusion of global administrator profiles.
The Emergence of TheHatman
The “TheHatman” profile initially emerged during the spring of 2026. By mid-August, this specific account displayed nine posts with zero forum reputation. The vendor published the first listings on August 1. These early offerings featured stolen databases from Hexaware Technologies and Kyndryl. Wyndham Hotels and InterContinental Hotels Group appeared on the following day. Subsequently, HCL Technologies emerged on August 7. The seller then added Tata Consultancy Services on August 10. Finally, Vodafone, McDonald’s, and Gap materialized on the illicit platform on August 16.
Analyzing the Compromised Records
The McDonald’s advertisement boasts over 1.7 million stolen records. In addition, Tata Consultancy Services allegedly suffers an exposure of 800,000 rows. Vodafone features 425,000 compromised entries in its specific listing. Meanwhile, HCL Technologies displays 250,000 exposed internal records. InterContinental Hotels Group lists 185,000 compromised rows. Kyndryl reveals 170,000 illicit entries. Gap exposes 80,000 internal corporate details. Hexaware Technologies contains 20,000 entries. Lastly, Wyndham Hotels shows 9,000 compromised rows. Currently, independent verification cannot confirm the complete volume of these massive databases.
The McDonald’s Data Extraction
Analysts investigated the McDonald’s sample most thoroughly. Ransomnews researchers examined 8,000 published rows and identified a distinct structural pattern. This internal structure strongly indicates an authentic extraction from Microsoft Entra ID. System administrators previously knew this platform as Azure Active Directory. The names of 19 specific fields precisely match the standard output of PowerShell commands. Administrators routinely use these exact commands to export corporate directories safely.
All 50 email domains within the published sample legitimately belong to McDonald’s. The file prominently contains the internal mcdonaldscorp.onmicrosoft.com domain address. It also exposes the corporate accounts of employees, restaurant staff, franchisees, and external contractors. Furthermore, it reveals shared internal mailbox details. Each row represents a distinct directory account. However, it does not necessarily represent an active, employed individual.
Authenticity Through Anomalies
Additionally, Ransomnews discovered distinct encoding errors within the dataset. Some job titles consistently truncate exactly after 30 characters. Consequently, researchers consider these technical anomalies as supplementary evidence of a genuine corporate extraction. Addresses, telephone dialing codes, and geographic locations align logically across most verified sample rows.
The published sample constitutes a mere 0.47 percent of the claimed 1.7 million records. Therefore, the total volume of the McDonald’s database remains entirely unverified. The file completely lacks account creation dates or last login timestamps. This specific omission prevents security analysts from determining the exact extraction timeframe. The verified rows contain no passwords, cryptographic hashes, payment details, or sensitive customer information.
Investigating the Attack Vectors
Cybersecurity firm Hudson Rock analyzed samples from several advertisements. The firm ultimately concluded these materials are highly likely authentic. They based this professional assessment on internal corporate addresses and specific field names. They also analyzed unique Microsoft domain structures. However, Hudson Rock did not confirm the total database volume. They also could not verify the exact data acquisition method used by the attacker.
“TheHatman” claims they utilized compromised credentials to execute this massive breach. Hudson Rock detected strong indications of recent Azure credential theft. Information stealers successfully targeted vulnerable users at TCS, Gap, HCL Technologies, and Kyndryl. Despite this evidence, researchers have not definitively proven a connection. They cannot confirm that “TheHatman” used these specific compromised credentials to download the massive directories.
The Danger of Stolen Session Tokens
Information stealers possess the dangerous capability to extract saved passwords and private browser contents. They also steal active authentication session tokens. Microsoft explicitly warns about the severe dangers of stolen session tokens. A stolen token empowers a malicious attacker to seamlessly impersonate a legitimate user. This unauthorized access continues until the token expires or an administrator forcibly revokes it. Analysts have not yet confirmed the application of this specific technique in “TheHatman’s” ongoing campaign.
Obtaining a corporate directory does not always require high-level global administrator privileges. Microsoft indicates that standard Entra directory members possess extensive default viewing permissions. By default, standard users can read almost all information concerning other users, internal groups, and enterprise applications. Global administrator rights are completely unnecessary for basic directory reading tasks. The exact access level of “TheHatman’s” compromised accounts remains entirely unknown.
Corporate Responses and Mitigations
Furthermore, Hudson Rock considers targeted phishing as a highly probable initial attack vector. They also suspect malicious third-party applications possessing excessive directory permissions. Researchers found absolutely no evidence of an undisclosed zero-day vulnerability within Microsoft Azure or Entra systems.
Tata Consultancy Services formally informed the stock exchange regarding this cybersecurity incident. Their internal review uncovered no conclusive evidence of a TCS system or client infrastructure compromise. The company categorizes the published details as basic, historical employee information. Furthermore, they assert someone gathered this specific data over four years ago. Therefore, sensitive client data, customer systems, and the core TCS operational infrastructure remain completely unaffected.
Denials and Outdated Information Claims
According to TCS, the attacker claimed they utilized widespread password spraying attacks. The threat actor also allegedly dispatched multiple multifactor authentication fatigue requests. TCS has actively utilized robust defensive measures against both techniques for over two years. The enterprise continues to vigilantly monitor its complex corporate infrastructure.
Similarly, HCLTech issued a formal public statement. Their initial investigation discovered zero compromise of internal systems or vital client resources. The corporation labeled the potentially exposed information as highly restricted and obsolete by several years. Nevertheless, they actively continue their comprehensive internal cybersecurity investigation.
Gap also formally announced the definitive results of their preliminary security review. They found no indications whatsoever of a corporate system breach. The retailer characterized the leaked information as limited, non-sensitive, and several years outdated.
The Persistent Threat of Phishing
Ultimately, TCS, HCLTech, and Gap consider the published information largely obsolete. Initial investigations by these three corporations revealed no signs of internal corporate system compromises. McDonald’s, Vodafone, Kyndryl, InterContinental Hotels Group, Hexaware Technologies, and Wyndham Hotels have not publicly confirmed a security breach.
Hudson Rock strongly warns that even archaic corporate directories facilitate highly targeted phishing attacks. Names, job titles, departments, telephone numbers, and manager details strongly empower criminals. They can easily impersonate technical support personnel or senior corporate executives. The explicit mention of global administrators and technical accounts heavily assists attackers. It helps them meticulously select high-value targets possessing elevated system privileges.
As of August 18, independent investigators have confirmed “TheHatman’s” dark web forum publications. They also verified the McDonald’s sample matches a genuine Entra ID extraction structure. However, the complete database volumes remain completely unverified. The currency of most records and recent unauthorized access to corporate systems also lack independent confirmation. Researchers discovered absolutely no indications of a direct breach of the core Microsoft Azure platform.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.