
A threat actor calling themselves “TheHatman” is claiming to have stolen approximately 3.64 million employee records from the Microsoft Azure directories of nine major corporations, posting data dumps on cybercriminal forums throughout mid-2026. The most recent dump, posted on August 16, advertised 1.7 million records allegedly from McDonald’s alone. The full list of affected organizations includes McDonald’s (1.7 million records), Tata Consultancy Services (800,000), Vodafone (425,000), HCL Technologies (250,000), InterContinental Hotels (185,000), Kyndryl (170,000), Gap Inc. (80,000), Hexaware (20,000), and Wyndham Hotels (9,000).
The stolen records reportedly contain names, employee IDs, email addresses, job titles, phone numbers, postal addresses, and service account details from Microsoft Entra ID (formerly Azure Active Directory) corporate tenants. TheHatman claims access was gained through compromised credentials and MFA fatigue — a technique where attackers flood users with authentication prompts until one is accidentally approved. Hudson Rock, which analyzed the dumps, confirmed they contain foundational corporate directory data including administrator account names that could enable targeted phishing. Several affected companies pushed back: both Tata Consultancy Services and Gap Inc. said their investigations found no credible evidence of a current breach, characterizing the data as old and limited in scope.
