In the darknet, the declared 3.64 million records from the corporate directories of Microsoft Azure and Entra were put on sale. The seller, under the pseudonym TheHatman, attributes the bases to nine major companies, including McDonald’s, Vodafone, Tata Consultancy Services and HCL Technologies. The ads mention the names of employees, positions, work phones, addresses, divisions, executives, technical accounts and global administrators.
The Hatman profile appeared in the spring of 2026. By mid-August, the account had nine publications and zero reputation on the forum. The first announcements were posted by the seller on August 1, offering Hexaware Technologies and Kyndryl. The next day appeared Wyndham Hotels and InterContinental Hotels Group, on August 7 followed by HCL Technologies, on August 10 the seller added Tata Consultancy Services. Vodafone, McDonald’s and Gap hit the venue on August 16.
The announcement of McDonald’s includes more than 1.7 million records. For Tata Consultancy Services, more than 800 thousand lines have been announced, Vodafone received 425 thousand, HCL Technologies - 250 thousand, InterContinental Hotels Group - 185 thousand, Kyndryl - 170 thousand, Gap - 80 thousand, Hexaware Technologies - 20 thousand, Wyndham Hotels - 9000. There is no independent confirmation of the total volume of the bases.
The most detailed sample of McDonald’s. Ransomnews specialists studied 8000 published lines and found a structure typical of the real unloading from Microsoft Entra ID, formerly known as Azure Active Directory. The names of the 19 fields correspond to the results of the Full-time PowerShell teams for the export of the corporate catalog.
All 50 mail domains from the sample are owned by McDonald’s. The file contains the internal domain mcdonaldscorp.onmicrosoft.com, corporate employee accounts, restaurant workers, franchisees, contractors and shared inboxes. One line denotes an account, but not always a separate active employee.
Ransomnews also found coding errors and the same cropping of some posts after 30 characters. The researchers called the features additional signs of the present unloading from the corporate system. Addresses, phone codes and countries in most of the verified lines are consistent with each other.
The published sample is 0.47% of the declared 1.7 million records, so the full volume of the base remains unconfirmed. The file does not contain the date of creating accounts or the last login, which does not allow you to determine the time of upload. There are no passwords, hashes, payment information or information about McDonald’s customers in the verified lines.
Hudson Rock analyzed samples from several ads and found the materials with a high probability of authentic. The valuation is based on corporate addresses, field names, and internal structures of Microsoft domains. Hudson Rock did not confirm the declared volume of bases and the exact way of obtaining information.
TheHatman claims to have used compromised credentials. Hudson Rock found signs of Azure's accounting data theft with infostilers in users of TCS, Gap, HCL Technologies and Kyndryl. The researchers did not determine whether TheHatman used the found credentials to unload the catalogs.
Infostilers are able to steal saved passwords, browser contents and active session tokens. Microsoft warns that the stolen token allows you to impersonate the user before the expiration or forced recall is over. The use of this method in the TheHatman campaign has not yet been confirmed.
Getting a corporate directory does not always require administrator rights. Microsoft indicates that regular Entra directory members by default can read almost all information about users, groups and applications. Global administrator rights are not required for regular directory reading. The Hatman account access level is unknown.
Hudson Rock also treats phishing and third-party applications with redundant permissions as possible ways to gain access. The researchers found no signs of an unknown vulnerability of Microsoft Azure or Entra.
Tata Consultancy Services told the exchange that the internal audit did not reveal convincing signs of compromise of TCS systems or customer infrastructure. The company considers the published information to be basic information about employees collected more than four years ago. Customer data, customer systems and TCS work infrastructure were not affected.
According to TCS, the attacker claimed a mass selection of common passwords and repeated sending of requests for multi-factor confirmation. TCS has been using protection against both techniques for more than two years and continues to observe corporate infrastructure.
HCLTech said the initial inspection did not find compromise of internal systems or customer resources. The company called the possible information limited and obsolete for several years, but continued the investigation.
Gap reported that the preliminary check did not reveal signs of hacking corporate systems. The company called the information limited, insensitive and obsolete for several years.
TCS, HCLTech and Gap consider the published information obsolete. The audits of the three companies at the time of the allegations did not reveal signs of compromise of corporate systems. McDonald’s, Vodafone, Kyndryl, InterContinental Hotels Group, Hexaware Technologies and Wyndham Hotels have not publicly confirmed the hack.
Hudson Rock warns that even older corporate directories help conduct targeted phishing. Names, positions, units, telephones and managers allow criminals to impersonate technical support staff or superiors. Mentioning global administrators and technical accounts helps to choose users with extended rights.
By August 18, the publication of TheHatman announcements and the compliance of the McDonald’s sample with the structure of this unloading of Entra ID have been confirmed. Full volumes of bases, the relevance of most records and recent access to corporate systems remain unconfirmed. The researchers did not find signs of hacking the Microsoft Azure platform.
The Hatman profile appeared in the spring of 2026. By mid-August, the account had nine publications and zero reputation on the forum. The first announcements were posted by the seller on August 1, offering Hexaware Technologies and Kyndryl. The next day appeared Wyndham Hotels and InterContinental Hotels Group, on August 7 followed by HCL Technologies, on August 10 the seller added Tata Consultancy Services. Vodafone, McDonald’s and Gap hit the venue on August 16.
The announcement of McDonald’s includes more than 1.7 million records. For Tata Consultancy Services, more than 800 thousand lines have been announced, Vodafone received 425 thousand, HCL Technologies - 250 thousand, InterContinental Hotels Group - 185 thousand, Kyndryl - 170 thousand, Gap - 80 thousand, Hexaware Technologies - 20 thousand, Wyndham Hotels - 9000. There is no independent confirmation of the total volume of the bases.
The most detailed sample of McDonald’s. Ransomnews specialists studied 8000 published lines and found a structure typical of the real unloading from Microsoft Entra ID, formerly known as Azure Active Directory. The names of the 19 fields correspond to the results of the Full-time PowerShell teams for the export of the corporate catalog.
All 50 mail domains from the sample are owned by McDonald’s. The file contains the internal domain mcdonaldscorp.onmicrosoft.com, corporate employee accounts, restaurant workers, franchisees, contractors and shared inboxes. One line denotes an account, but not always a separate active employee.
Ransomnews also found coding errors and the same cropping of some posts after 30 characters. The researchers called the features additional signs of the present unloading from the corporate system. Addresses, phone codes and countries in most of the verified lines are consistent with each other.
The published sample is 0.47% of the declared 1.7 million records, so the full volume of the base remains unconfirmed. The file does not contain the date of creating accounts or the last login, which does not allow you to determine the time of upload. There are no passwords, hashes, payment information or information about McDonald’s customers in the verified lines.
Hudson Rock analyzed samples from several ads and found the materials with a high probability of authentic. The valuation is based on corporate addresses, field names, and internal structures of Microsoft domains. Hudson Rock did not confirm the declared volume of bases and the exact way of obtaining information.
TheHatman claims to have used compromised credentials. Hudson Rock found signs of Azure's accounting data theft with infostilers in users of TCS, Gap, HCL Technologies and Kyndryl. The researchers did not determine whether TheHatman used the found credentials to unload the catalogs.
Infostilers are able to steal saved passwords, browser contents and active session tokens. Microsoft warns that the stolen token allows you to impersonate the user before the expiration or forced recall is over. The use of this method in the TheHatman campaign has not yet been confirmed.
Getting a corporate directory does not always require administrator rights. Microsoft indicates that regular Entra directory members by default can read almost all information about users, groups and applications. Global administrator rights are not required for regular directory reading. The Hatman account access level is unknown.
Hudson Rock also treats phishing and third-party applications with redundant permissions as possible ways to gain access. The researchers found no signs of an unknown vulnerability of Microsoft Azure or Entra.
Tata Consultancy Services told the exchange that the internal audit did not reveal convincing signs of compromise of TCS systems or customer infrastructure. The company considers the published information to be basic information about employees collected more than four years ago. Customer data, customer systems and TCS work infrastructure were not affected.
According to TCS, the attacker claimed a mass selection of common passwords and repeated sending of requests for multi-factor confirmation. TCS has been using protection against both techniques for more than two years and continues to observe corporate infrastructure.
HCLTech said the initial inspection did not find compromise of internal systems or customer resources. The company called the possible information limited and obsolete for several years, but continued the investigation.
Gap reported that the preliminary check did not reveal signs of hacking corporate systems. The company called the information limited, insensitive and obsolete for several years.
TCS, HCLTech and Gap consider the published information obsolete. The audits of the three companies at the time of the allegations did not reveal signs of compromise of corporate systems. McDonald’s, Vodafone, Kyndryl, InterContinental Hotels Group, Hexaware Technologies and Wyndham Hotels have not publicly confirmed the hack.
Hudson Rock warns that even older corporate directories help conduct targeted phishing. Names, positions, units, telephones and managers allow criminals to impersonate technical support staff or superiors. Mentioning global administrators and technical accounts helps to choose users with extended rights.
By August 18, the publication of TheHatman announcements and the compliance of the McDonald’s sample with the structure of this unloading of Entra ID have been confirmed. Full volumes of bases, the relevance of most records and recent access to corporate systems remain unconfirmed. The researchers did not find signs of hacking the Microsoft Azure platform.