A threat actor operating under the alias "TheHatman" has claimed to have stolen 3.64 million employee records from the Microsoft Azure infrastructure of several major corporations, including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. The alleged breaches were advertised in multiple posts starting July 31st, with the most recent claim on August 16th involving 1.7 million employee records from McDonald's.
The attacker asserts that the data was exfiltrated directly from Azure tenants using compromised credentials, and that the information includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, and service account details. TheHatman claims to have used password spraying and Multi-Factor Authentication (MFA) fatigue as attack vectors to gain initial access.
Among the largest alleged dumps are 1.7 million records from McDonald's and over 800,000 records from Tata Consultancy Services (TCS). Other organizations listed include Vodafone with 425,000 records, HCL Technologies with 250,000, InterContinental Hotels with 185,000, and Kyndryl with 170,000. Smaller alleged breaches include Gap Inc. with 80,000 records, Wyndham Hotels with 9,000, and Hexaware with 20,000. For each advertised database, the threat actor provided a sample for verification.
However, several affected companies have disputed the claims. Tata Consultancy Services, in a notification to the National Stock Exchange of India, stated that an investigation found no credible evidence of a breach of its systems or customer environments. TCS added that the details in question appear to be at least four years old, contain only basic employee information, and that the company has had strong safeguards against password spraying and MFA fatigue for over two years.
Gap Inc. also reported finding no evidence of a breach of its corporate systems. A spokesperson indicated that their preliminary investigation suggests the data is limited in scope, non-sensitive, and dates back several years.
Cybercrime intelligence firm Hudson Rock analyzed the leaked samples and confirmed they contain "foundational corporate directory attributes," including active domains and tenant-specific .onmicrosoft.com structures. The firm also noted the presence of service accounts and global administrator names, which could potentially be exploited for social engineering and spearphishing attacks. While Hudson Rock expressed high confidence in the authenticity of the data itself, the precise access vector and exfiltration method remain unconfirmed.






