Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Lake Powell hits record low, threatening key water and electricity supply for millions

    August 18, 2026

    Illinois pesticide fees meant for oversight are funding broader state operations 

    August 18, 2026

    Supporting young people so they don’t become Neets | Youth unemployment

    August 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Lake Powell hits record low, threatening key water and electricity supply for millions
    • Illinois pesticide fees meant for oversight are funding broader state operations 
    • Supporting young people so they don’t become Neets | Youth unemployment
    • White House launches personal attack on CNN reporter over question to Trump | Donald Trump
    • Greece sabotages its own plans to reverse the brain drain of scientists – POLITICO
    • Trump Votes by Mail Again in Florida
    • AI automation startup Relay shuts down, staff joins Google’s Chrome team
    • Pokémon Center data breach exposes customer info, cancels some orders
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hacker claims 3.6 million Azure account records stolen from major companies

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 18, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.

    ​Starting July 31st, multiple posts from someone using the alias “TheHatman” advertised data dumps from major organizations, including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl.

    In total, the threat actor claims to have 3.64 million data records, with the most recent breach posted on Sunday, containing an alleged 1.7 million employee records from McDonalds.

    image

    “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” the threat actor says in the post.

    TheHatman says that the information includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records.

    Cybercriminal advertising McDonald's database with employee records
    Cybercriminal advertising McDonald’s database with employee records
    source: BleepingComputer

    The second-largest data dump advertised is allegedly stolen from Tata Consultancy: an Azure dump with more than 800,000 employee records “downloaded directly from Azure Tenant using compromised credentials,” the cybercriminal states.

    However, in a notification to the National Stock Exchange of India, Tata says it investigated the alleged breach and found no “credible evidence of a breach of TCS systems or customer environments.”

    The company states that the details appear to be at least four years old and include only basic employee information.

    “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years,” Tata says.

    The company also added that it reviewed its defenses and found that they remain effective.

    In a statement for BleepingComputer, a Gap Inc. spokesperson said that the company found no evidence of a breach. Additionally, the advertised data is not sensitive in nature and “dated back to several years ago.”

    “Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” the Gap Inc. representative said.

    Between July 31st and August 16, TheHatman has offered to sell data dumps for the following organizations:











    Company Size Type Data type
    McDonalds 1.7+ million records Azure Internal Employee Dump Full Name, Email, Title, Phone, Address
    Gap Inc. 80,000+ records Azure Internal Employee Dump Full Name, Email, Title, Phone, Address
    Vodafone 425,000+ records Azure Internal Employee Dump Full Name, Email, Title, Phone, Address
    TCS (Tata Consultancy) 800,000+ records Azure dump Full Name, Email, Title, Phone, Address
    HCL Technologies 250,000+ records Azure dump Full Name, Email, Title, Phone, Address
    InterContinental Hotels 185,000+ records Azure dump Full Name, Email, Title, Phone, Address
    Wyndham Hotels 9,000+ records Azure/Entra dump Full Name, Email, Title, Phone, Address
    Hexaware  20,000+ records Azure/Entra dump Full Name, Email, Employee ID, Phone, Address
    Kyndryl.com 170,000+ records Azure/Entra dump Employee accounts, service accounts, and other tenant account records.

     

    For each advertised database, TheHatman also provided a sample database for potential buyers to verify the data.

    Cybercrime intelligence company Hudson Rock analyzed the leaks and confirmed that they contain “foundational corporate directory attributes” and a clear data structure with fields that include “active domains and tenant-specific .onmicrosoft.com structures.”

    According to the cybersecurity firm, the dumps also contain service accounts and the names of global administrators, which could facilitate social engineering and spearphishing attacks.

    While Hudson Rock has high confidence that the data is authentic, the access vector and exfiltration method remain unknown. BleepingComputer has not been able to independently verify that the data is authentic.

    BleepingComputer contacted the listed companies about the potential breach but had not received comments by the time of publication.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    account Azure claims companies Hacker major Million records stolen
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Pokémon Center data breach exposes customer info, cancels some orders

    Texas activist’s claims of Indigenous ancestry face scrutiny

    Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

    Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

    Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

    NASA Selects Companies to Provide Payload Processing Services

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Lake Powell hits record low, threatening key water and electricity supply for millions

    August 18, 2026

    Illinois pesticide fees meant for oversight are funding broader state operations 

    August 18, 2026

    Supporting young people so they don’t become Neets | Youth unemployment

    August 18, 2026

    White House launches personal attack on CNN reporter over question to Trump | Donald Trump

    August 18, 2026
    Latest Posts

    Wisconsin’s Democratic primary for governor: a look at the 5 remaining

    July 27, 2026

    UK CO2 storage project that will reuse existing infrastructure secures lease

    July 27, 2026

    Bangladesh shipbreakers push back against stricter environmental standards

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Lake Powell hits record low, threatening key water and electricity supply for millions

    August 18, 2026

    Illinois pesticide fees meant for oversight are funding broader state operations 

    August 18, 2026

    Supporting young people so they don’t become Neets | Youth unemployment

    August 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.