The TheHatman Azure breaches: who was named, and who is actually at risk

Nine companies, 3.6 million staff records, McDonald’s and Vodafone at the top of the list — all of it pulled from corporate directories rather than customer databases. Here is what was taken, who disputes it, and the honest answer if you are wondering whether it reaches you.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

A seller calling himself TheHatman spent August 2026 offering the internal staff directories of nine large companies — McDonald’s, Vodafone, TCS, HCL, IHG, Kyndryl, Gap, Hexaware and Wyndham — for a combined 3.6 million records. The data is employee material: names, work emails, job titles, phone numbers, employee IDs, reporting lines, service accounts. No customer accounts, passwords or payment cards have been claimed. Microsoft’s platform was not breached; the claim is that working logins were used to walk into nine company tenants. Two of the nine, TCS and Gap, dispute that they were breached at all. Nothing has been published as a searchable set, so no service can look you up against it.

The nine companies named

Record counts are the seller’s own figures from the forum listings, not a verified inventory — numbers in this trade are routinely inflated. Two companies have responded publicly as of 31 August 2026; the rest had not commented by the time the reports were published.

Sources: listings reported by BleepingComputer, The Register and Cybernews, 17–18 August 2026; company statements as given to those outlets and, in the case of TCS, filed with India’s National Stock Exchange.
CompanyRecords claimedWhat the company has said
McDonald’s1.7 million+No public statement reported.
Tata Consultancy Services800,000+Told India’s National Stock Exchange it “has not found any credible evidence of a breach of TCS systems”, and that the data looks more than four years old and limited to basic employee details.
Vodafone425,000+No public statement reported.
HCL Technologies250,000+No public statement reported.
IHG Hotels & Resorts185,000+No public statement reported.
Kyndryl170,000+No public statement reported.
Gap Inc.80,000+Said there is “no evidence to suggest that our corporate systems have been compromised”, and described the data as non-sensitive and several years old.
Hexaware Technologies20,000+No public statement reported.
Wyndham Hotels & Resorts9,000+No public statement reported.

Your employer’s directory is one half. The public half is the one you can close.

A work title and a desk number get useful once someone pairs them with your home address, mobile and relatives — which are published, free to read, on hundreds of people-search sites. PersProtect shows which known breaches hold your email and where your details appear across 499 broker and people-search sites, then files the removals for you.

Check my exposure — free →

1. What happened, in order

Between 31 July and mid-August 2026 a seller using the name TheHatman posted a run of listings across the criminal forums DarkForum, PwnForums and BreachForumsSt, each one offering the internal directory of a different large company. By 16 August there were nine, totalling around 3.6 million records, with McDonald’s the largest at more than 1.7 million. The story broke publicly on 17 August through BleepingComputer, The Register, Cybernews and Security Affairs, with Help Net Security following on the 18th. The common thread the reporters drew out was the platform: every listing described the same kind of export from a company’s Microsoft Azure and Entra ID tenant, the system that holds its staff directory.

2. Nobody broke Azure

The headline reads like a cloud platform failed, and it is worth being precise that it did not. Entra ID is where a company keeps its own list of employees; the claim is that someone signed in to nine of those company tenants with credentials that worked and downloaded what any logged-in user could already see. Hudson Rock, whose researchers went through samples of the data, put the argument for that reading simply: a real flaw in the platform itself would not have produced a victim list of nine large firms, it would have produced thousands. The seller claims password spraying and repeated approval prompts got them in. Researchers point instead at the ordinary routes — malware on a staff laptop that hands over saved passwords and live session cookies, a phishing page that caught an administrator, a tenant where multi-factor was never enforced, an old integration with more access than anyone remembered.

3. What is in a directory export

The listings describe full names, work email addresses, job titles, departments, office locations, phone numbers, postal addresses, employee IDs, reporting lines, group memberships and service accounts — and, in some of the sets, the names of accounts holding global administrator rights. What is not described anywhere is a customer database: no consumer logins, no loyalty balances, no payment cards, no Social Security numbers. That is the seller’s own inventory rather than a company denial, and it matches what the system being copied actually holds. It also explains why no notification letters have gone out — this is a workplace exposure, and the people in it are employees and contractors.

4. The honest answer to “am I affected”

If you are a customer of McDonald’s, Vodafone, IHG, Wyndham or Gap: on the evidence today, no. Nothing consumer-facing has been claimed, nothing has been published as a searchable set, and no lookup anywhere can check you against it. If you work at one of the nine, or did in the past few years, assume your work contact details and your place in the org chart are in circulation, and that the practical consequence is a well-informed approach arriving at work rather than anything happening to your personal accounts. TCS’s point that the data looks over four years old cuts both ways: a job title from 2022 is stale, but a name, a mobile number and a former employer are not.

5. Why a staff list is the valuable part

Stolen passwords expire the moment someone changes them. An org chart does not. Knowing who reports to whom, what the internal email format looks like, which office a named person sits in and which accounts carry administrator rights is what turns a mass phishing run into a message that names a real colleague and asks for something that sounds like Tuesday. That is the specific risk researchers raised about the service accounts and global administrator names in these sets, and it is why a leak with no passwords in it still buys the buyer something. The defence is procedural rather than technical: verify anything about money, credentials or approvals through a channel you opened yourself. The Cl0p Windchill campaign produced the same shape of exposure from engineering documents instead of directories.

6. What is worth doing this week

If you are on the staff list: change the work password if it has stood since 2022, check that multi-factor is on and running through an app or a hardware key rather than SMS, and treat an unexpected approval prompt as an attack in progress rather than a glitch — deny it and tell your security team. For everyone, named employer or not, the durable move is the other half of the picture. Your work number being known matters far less than your home address, mobile and relatives sitting on people-search sites where anyone can read them, and that half you can actually remove.

Common questions

The TheHatman Azure breaches, answered

I eat at McDonald’s and I have the app. Is my account in this?

Nothing published says it is. What is being sold is described as staff directory material — employee names, work emails, job titles, desk and mobile numbers, employee IDs, reporting lines, service accounts. Customer accounts, app logins, loyalty balances and payment cards do not appear in the seller’s own listing, and no company has notified customers about it. The people with something at stake here are employees and contractors of the named companies, not the people who buy from them.

Was Microsoft or Azure hacked?

No, and that distinction is the whole story. Azure and Entra ID are where a company keeps its own staff directory; the claim is that someone walked into nine of those company directories with working logins and copied what an ordinary user could already see. Researchers at Hudson Rock, who examined samples, made the point plainly: a genuine flaw in the platform would have hit far more than nine large firms. Nothing here suggests a hole in Microsoft’s software.

So how did they get the logins?

The seller claims password spraying and MFA fatigue — trying one common password across thousands of accounts, then bombarding whoever it fits with approval prompts until somebody taps yes. Researchers add the likelier everyday routes: information-stealing malware on an employee’s computer, which lifts saved browser passwords and live session cookies; a phishing page that caught an administrator; a tenant portal where multi-factor authentication was never enforced; or a third-party integration holding more read access than anyone remembered granting. None of that has been confirmed by the companies.

Two of the nine deny it. Who is right?

Both things can be true at once, which is what makes these stories confusing. TCS and Gap both say their systems were not broken into, and TCS adds that the data looks over four years old. A directory export that left a company in 2022 — through a contractor laptop, an old integration, a former administrator — is still real data about real people, and it is also, accurately, not a break-in this month. Hudson Rock’s read of the samples was that the material is highly likely authentic. Treat the record counts as the seller’s marketing and the underlying data as probably real but of unknown vintage.

Can I check whether my details are in it?

Not through any lookup, including ours. This has been offered for sale on criminal forums rather than published, so it has not reached the known breach databases our free check runs against — and it has not reached anyone else’s. An empty result for this campaign means nothing is indexed, not that you are clear. Anything advertising a “TheHatman leak checker” is either guessing or harvesting the details you type into it.

I work at one of these companies. What should I actually do?

Assume your name, title, work number and who you report to are known to whoever buys this, and that the first use will be a message that sounds informed. Change your work password if you have not since 2022 and make sure multi-factor is on for the account, ideally with an app or a key rather than SMS. Tell your security team you saw the reports — they may already be forcing resets. And set one rule for yourself: any request involving money, credentials or an approval prompt gets verified through a channel you started, not the one it arrived in.

Why is a staff directory worth anything to criminals?

Because it removes the guesswork from a scam. Knowing that a named person is a finance manager in a named office, who their manager is, what the internal email format looks like and which accounts hold administrator rights turns a generic phishing blast into a message that names the right colleague and asks for something plausible. Security researchers flagged the service accounts and global administrator names in this data as the part worth worrying about, precisely because they map out where the keys sit.

Nothing financial leaked. Does this still matter for me personally?

It matters in one narrow way that people underrate. Work numbers and office addresses are the seed a stranger uses to find the rest, and the rest — home address, mobile, relatives, past addresses — is sitting in public on people-search sites that anybody can read for free. The corporate directory is the half you cannot do anything about. The published half you can, and shrinking it is what makes a targeted approach fall apart.

A stranger with your job title still needs your address.

See which sites publish your home address, phone number and relatives right now — free, in about a minute.

Run a free exposure scan →