A cybercriminal using the handle “TheHatman” claims to be selling more than 3.6 million employee-directory records obtained from the Microsoft Entra ID environments of major companies including McDonald’s, Vodafone, and Tata Consultancy Services.
The seller began advertising the stolen databases across cybercrime forums including DarkForum, PwnForums, and BreachForumsSt between July 31 and mid-August.
The largest individual dataset claims to expose over 1.7 million records from McDonald’s Corporation, advertised as an “internal employee dump downloaded directly from Azure Tenant using compromised credentials.”

Other prominent enterprise listings include:
- Tata Consultancy Services (TCS): ~800,000 records
- Vodafone: ~425,000 records
- HCL Technologies: ~250,000 records
- InterContinental Hotels Group (IHG): ~185,000 records
- Kyndryl: ~170,000 records
- Gap Inc.: ~80,000 records
- Hexaware Technologies: ~20,000 records
- Wyndham Hotels: ~9,000 records
The datasets consist of core enterprise directory attributes: full names, employee IDs, phone numbers, postal addresses, corporate email addresses (including native .onmicrosoft.com routing), job titles, manager assignments, group memberships, and lists of service accounts and Global Administrators.
Targeted theft over platform flaws
Threat intelligence firm Hudson Rock assessed samples of the advertised data as “highly likely authentic,” citing corporate email structures and fields consistent with Microsoft Entra ID directory exports. However, the datasets’ provenance, age, and method of extraction have not been independently confirmed.
“The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations,” Hudson Rock noted.
Rather than a zero-day flaw in Azure itself, security analysts attribute the breaches to infostealer malware, which pilfers saved browser passwords and session tokens from infected employee computers. Hudson Rock identified compromised credentials originating from infostealer logs tied to several affected companies, including TCS, Gap, HCL Technologies, and Kyndryl.
According to BleepingComputer, both TCS and Gap have pushed back on claims of a recent network breach. TCS informed the National Stock Exchange of India that its review found no credible evidence of an intrusion, adding that the data appears to be more than four years old. A Gap spokesperson similarly stated that preliminary reviews showed no corporate systems were compromised and that the advertised data was non-sensitive and dated.

The real risk is what comes next
Even if some of the records are old, detailed employee directories can become valuable attack material. Knowing an employee’s manager, job title, phone number and corporate email address gives criminals enough context to make phishing or impersonation attempts appear credible.
The exposure of administrator and service-account information raises the stakes further because it can help attackers prioritize accounts that could provide deeper access. For companies, the incident underscores a shift in cloud security: protecting passwords alone is no longer enough. Organizations also need to watch for stolen session tokens and infostealer infections, limit directory visibility and tightly control applications with access to Entra environments.
For employees, unexpected calls or messages that already know their job title, manager or workplace details deserve extra scrutiny.
Read more: Learn how attackers are moving beyond password theft to target Microsoft authentication flows and session tokens in Phishing Tactics Target Session Tokens and Deliver Malware.





