August 24, 2026
By esentry Team

Hatman : Millions of Employee Records for Sale

A cybercriminal operating under the name “TheHatman” has posted large datasets allegedly taken from the Azure and Microsoft Entra environments of several major organizations, including McDonald's, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, Kyndryl, Gap, and major hotel groups.

The listings reportedly contain more than 3.6 million records in total. The exposed information includes employee names, corporate email addresses, phone numbers, job titles, departments, managers, group memberships and details relating to privileged accounts.

While the claims have not been confirmed for every organization named, the examined samples found the data consistent with genuine Azure directory information. TCS, however, has disputed claims of a breach and said its investigation found no credible evidence of compromise.

What Was Stolen?

The data reportedly includes:

  • Employee names and corporate email addresses
  • Phone numbers and workplace information
  • Job titles and departments
  • Manager and reporting relationships
  • Group memberships
  • Service accounts
  • Information identifying privileged accounts

How Did the Attackers Get In?

There is currently no evidence of an Azure zero-day or a vulnerability in Microsoft's cloud platform being responsible for the campaign. Instead, we believe compromised credentials may have provided the attackers with access to the affected environments. Hudson Rock linked credentials associated with several of the organizations to infections involving infostealer malware. An infostealer is malware designed to quietly collect information from an infected computer.

Depending on the malware, it can steal:

  • Passwords
  • Browser credentials
  • Cookies
  • Session information
  • Other sensitive data

Once attackers obtain valid credentials or session information, they may be able to access cloud services as the legitimate user.

Why Azure and Entra Data Matters

Microsoft Azure provides cloud infrastructure and services, while Microsoft Entra ID manages identities and access to those services. Entra can contain a detailed directory of an organization's people, accounts and access relationships. If attackers obtain unauthorized access, that directory can reveal the structure of the organization.

A criminal who knows that an employee works in Finance, reports to a particular manager and handles supplier payments has enough information to create a much more believable scam than a random phishing email.

This could increase the risk of:

  • Targeted phishing
  • Business Email Compromise (BEC)
  • Executive impersonation
  • Credential theft
  • Further account compromise

Why Privileged Accounts Are a Major Concern

A privileged account is an account with greater access than an ordinary employee account. Some can manage users, applications and security settings across an organization's environment.

Attackers don't necessarily need the password immediately. Knowing who holds the keys can be enough to plan the next attack. This makes exposed administrator information particularly valuable for targeted social engineering.

What Organizations Should Do

  1. Check for Exposed Credentials: Organizations should determine whether employee or administrator credentials have appeared in known infostealer logs or other threat-intelligence sources.

Priority should be given to:

  • Administrators
  • Finance employees
  • Executives
  • IT personnel
  • Service accounts
  1. Reset Compromised Credentials: Any confirmed compromised credentials should be reset immediately. Where there is a possibility that session information was stolen, organizations should also revoke active sessions and authentication tokens rather than relying on a password reset alone.
  1. Strengthen Identity Protection: Organizations should enforce:
  • Multi-Factor Authentication (MFA)
  • Conditional Access policies
  • Least-privilege access
  • Strong controls around administrator accounts
  • Regular reviews of inactive and unnecessary accounts
  1. Monitor Azure and Entra Activity: Security teams should investigate unusual:
  • Sign-in locations and devices
  • Authentication activity
  • Privilege changes
  • Directory queries
  • Application permissions
  1. Watch for Follow-Up Phishing: Employees should be particularly cautious about emails or messages that contain accurate internal information. Requests involving payments, password resets, banking details or sensitive documents should be independently verified.
  1. Monitor the Threat Landscape: Organizations should monitor underground forums and threat-intelligence sources for leaked credentials, employee information and references to their infrastructure.

Conclusion

Don't Let Your Employee Directory Become an Attacker's Target List. Your organization's cloud environment can be properly configured and still be exposed if an employee's credentials are stolen. Secure the identity, monitor the access and know what is exposed.

Follow esentry for timely threat intelligence, emerging cyber threats and practical security advisories that help organizations identify risks before they become costly incidents.