Hacker Claims 3.64 Million Employee Records Stolen From Azure
TheHatman claims Azure-linked employee data breaches have exposed around 3.64 million records belonging to workers at several major companies, including McDonald’s, Vodafone, Gap, and Tata Consultancy Services.
The threat actor began advertising the databases on July 31, 2026, claiming the information came from corporate Microsoft Azure environments accessed with compromised credentials.
However, several companies dispute the breach claims, while security researchers say they cannot confirm exactly how the attacker obtained the data.
TheHatman claims 3.64 million employee records
The alleged victims include McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services (TCS), HCL Technologies, InterContinental Hotels Group (IHG), and Kyndryl.
TheHatman claims the largest database contains approximately 1.7 million McDonald’s employee records downloaded directly from the company’s Azure tenant.
Another advertised dataset allegedly includes more than 800,000 TCS employee records.
According to the attacker, compromised credentials provided access to the environments rather than a vulnerability in Microsoft’s Azure infrastructure.
TCS disputes the breach claims
TheHatman claims password spraying and MFA fatigue attacks helped compromise TCS accounts and gain access to its Azure tenant.
TCS, however, says its investigation found no credible evidence that attackers breached its systems or customer environments.
The company says the advertised information appears to be at least four years old and contains only basic employee information.
TCS also says it has maintained protections against password spraying and MFA fatigue attacks for more than two years.
Gap finds no evidence of a corporate breach
Gap Inc. has also disputed the attacker’s claims.
The company says it found no evidence that its corporate systems were compromised and described the advertised information as limited, non-sensitive, and several years old.
Those findings raise questions about whether TheHatman obtained the records through recent Azure intrusions or collected older information from another source.
Researchers say the employee data appears authentic
Hudson Rock analyzed samples taken from the databases advertised by TheHatman.
The cybersecurity company says the samples contain corporate directory information, including active domains, tenant-specific .onmicrosoft.com structures, service accounts, and the names of global administrators.
Hudson Rock says it has high confidence that the data itself is authentic.
However, researchers could not verify how TheHatman gained access to the information or confirm the claimed Azure exfiltration method.
The attacker has reportedly provided samples to prospective buyers to demonstrate that the advertised databases contain legitimate information.
Employee directory data could still help attackers
Even basic corporate directory information can create security risks when it exposes service accounts, administrators, and employee identities.
Attackers could use that information for spearphishing, social engineering, credential attacks, or attempts to impersonate employees and administrators.
Information identifying privileged accounts could also help attackers focus future credential attacks on higher-value targets.
Azure breach claims remain unverified
The full datasets and TheHatman’s claimed method of accessing Azure environments have not been independently verified.
The presence of legitimate-looking employee records does not necessarily mean attackers compromised Microsoft Azure itself.
The information could have come from compromised individual credentials, older datasets, previous security incidents, or another unidentified source.
Some of the organizations named by TheHatman explicitly say they have found no evidence of a recent breach, making it important to distinguish the authenticity of individual records from the attacker’s broader claims about how they obtained them.
In other security news, Microsoft finally patched the LegacyHive Windows zero-day, while the company is also rushing to fix ShieldBreak after a Defender patch bypass.
Meanwhile, CoolClient malware now hides behind a Windows rootkit.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages