top of page

TheHatman claims 3.64 million Azure/Entra records: what should businesses know?

Aug 20
4 min read

Between July 31 and August 16, 2026, a threat actor known as TheHatman advertised approximately 3.64 million records allegedly obtained from the Azure/Entra environments of nine major companies using compromised credentials. Hudson Rock assessed the exposed samples as credible, but the exact intrusion method remains unconfirmed. No specific CVE has been linked to the campaign.

An internal employee directory may not contain passwords, but it can still become a valuable asset for cybercriminals if it reveals who reports to whom, which accounts hold elevated privileges, and which teams operate critical business functions. That is the central concern surrounding datasets TheHatman claims were extracted from Microsoft Azure and Microsoft Entra tenants belonging to several large organizations.

azure-entra-data-theft-campaign
Warning: Azure Entra data theft campaign

What happened in the TheHatman campaign?

TheHatman began advertising datasets on cybercrime forums on July 31, 2026. By August 16, the threat actor had posted data allegedly associated with at least nine major companies, totaling approximately 3.64 million records according to the attacker’s claims.

The organizations named include McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels Group (IHG), Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels. TheHatman claimed the information was downloaded directly from Azure or Entra tenants through compromised credentials.

Which figures stand out from the TheHatman campaign?

McDonald’s represents the largest dataset in TheHatman’s listings, with more than 1.7 million records, followed by TCS with more than 800,000 and Vodafone with approximately 425,000. The figures below reflect claims made by the threat actor and should not be interpreted as independently confirmed breach counts.

Organization named

Records claimed

McDonald’s Corporation

More than 1.7 million

Tata Consultancy Services

More than 800,000

Vodafone

About 425,000

HCL Technologies

About 250,000

InterContinental Hotels Group

About 185,000

Kyndryl

About 170,000

Gap Inc.

More than 80,000

Hexaware Technologies

More than 20,000

Wyndham Hotels

More than 9,000

The exposed samples were reported to include employee names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, departments, managers, group memberships, service accounts, and, in some cases, information identifying Global Administrator accounts.

The significance therefore goes beyond record volume. Organizational charts and privileged-account information can help attackers identify high-value targets for spear-phishing, Business Email Compromise (BEC), and subsequent attempts to gain additional access.

How can stolen credentials lead to Azure data exposure?

The initial access method used by TheHatman has not been independently confirmed. The threat actor claims compromised credentials were used, while Hudson Rock identified Azure-related credentials associated with infostealer-infected systems at some of the organizations named. That supports a credential-theft hypothesis, but it does not prove a single attack vector was used against every organization.

Microsoft recommends that when account impersonation is suspected, administrators consider actions including resetting passwords, enforcing MFA, disabling accounts where appropriate, and revoking refresh and access tokens.

For privileged accounts, identity governance should extend beyond MFA. Organizations also need to control the lifecycle of privileges, reduce unnecessary access, and monitor how privileged identities are used. IPSIP’s overview of Privileged Access Management and the Principle of Least Privilege provides additional context on limiting the potential impact of compromised identities.

What should Microsoft Azure customers do now?

The first priority is to determine whether accounts, tokens, or endpoints show signs of compromise. Microsoft Entra provides capabilities for reviewing risky users and risky sign-ins, and Microsoft recommends remediating high-risk identities rather than relying only on manual monitoring.

Priority checklist for IT and security teams:

  •  Review Microsoft Entra sign-in logs, risky users, and authentication attempts from unusual locations, devices, or applications.

  •  Reset credentials for suspected accounts and revoke active sessions or tokens where necessary.

  •  Require phishing-resistant MFA for Global Administrator and other privileged accounts.

  •  Review service accounts, dormant accounts, and permissions that are no longer required.

  •  Inspect OAuth applications, API permissions, and third-party integrations for excessive access.

  •  Check endpoints for infostealers, credential dumping, and browser-session theft.

  •  Centralize Microsoft Entra, Microsoft 365, endpoint, and cloud workload logs.

  •  Prepare incident-response procedures for spear-phishing or BEC campaigns that use real employee and management information.

CISA also recommends phishing-resistant MFA, appropriate cloud logging, and centralized monitoring of authentication and access events for organizations using cloud services.

What does IPSIP Vietnam’s expert perspective suggest?

Available evidence is more consistent with identity compromise than exploitation of a known Azure CVE. This differs from cloud vulnerability incidents such as CosmosEscape affecting Azure Cosmos DB, where the issue was tied directly to a cloud service component.

Directory information may not constitute sensitive business secrets by itself, but it can reveal organizational structure, administrators, service accounts, and internal reporting relationships. This can improve the effectiveness of spear-phishing, BEC, and follow-on access attempts.

Cloud defense needs to connect three areas: endpoint protection, identity governance, and continuous monitoring. Enabling MFA while overlooking session tokens, OAuth applications, or infected endpoints can still leave meaningful gaps.

For organizations in Vietnam using Microsoft Azure and Microsoft Entra, immediate priorities should include reviewing risky identities, sessions, privileged accounts, application permissions, and endpoints for signs of infostealer activity. Longer term, identity governance, cloud monitoring, and incident response should operate as continuous programs rather than controls activated only after data appears on a cybercrime forum.

References

follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
bottom of page