A crook calling themselves TheHatman is reportedly selling millions of employee records allegedly lifted from the Microsoft Azure environments of nine major firms, including McDonald's, Vodafone and TCS. For UK buyers, the case is a fresh reminder to secure identity and access management before credentials, not code, become the way in.
View the data behind this chart
| McDonald's | TCS | Vodafone | HCL Tech | |
|---|---|---|---|---|
| Records (thousands) | k record…1700 | k record…800 | k record…425 | k record…250 |
What's being claimed, and by whom
According to research published by Hudson Rock and reported by The Register, a threat actor using the handle TheHatman is advertising employee data allegedly exported from Azure directory services across nine organisations. McDonald's tops the list with 1.7 million records reportedly for sale, followed by Tata Consultancy Services at 800,000, Vodafone at 425,000 and HCL Technologies at 250,000. IHG Hotels & Resorts, Kyndryl, Gap, Hexaware Technologies and Wyndham Hotels & Resorts round out the alleged haul.
Hudson Rock assessed the data as "highly likely authentic", pointing to corporate email formats and structures consistent with Azure directory exports. Samples reportedly go well beyond names and email addresses, including phone numbers, physical addresses, employee IDs, job titles, reporting lines, group memberships and service account details — with some records reportedly flagging accounts holding Global Administrator privileges.
TCS says its systems weren't breached — here's why that matters
Tata Consultancy Services told its stock exchange, in a statement shared with The Register, that it found "no credible evidence of a breach of TCS systems or customer environments" and that the referenced information "appears to be more than four years old and limited to basic employee information." TCS also said the attacker claimed to have used password spray and MFA-fatigue techniques, and that it has had "strong safeguards" against such methods in place for over two years.
This distinction matters for UK buyers assessing their own third-party exposure. Old, low-sensitivity employee data circulating on a criminal forum is a materially different risk than live customer or operational data — but it still fuels convincing phishing and social-engineering campaigns, particularly when combined with details on who holds Global Administrator rights.
Infostealers, not a zero-day: the pattern that should worry buyers
Hudson Rock's own infostealer database reportedly contained compromised Microsoft cloud credentials tied to most of the named companies, though it could not directly link those credentials to TheHatman's claimed access. Its assessment: "it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure," noting that a genuine platform flaw would likely have hit a much broader spread of smaller organisations too.
That framing has a practical implication for UK IT leaders: this looks less like a Microsoft platform failure and more like a credential-hygiene failure at scale. The Register lists several plausible access routes — infostealer-harvested credentials or session cookies, phishing, weak or absent multifactor authentication, and overly permissive third-party applications — none of which require a software patch to close.

Tenant isolation has form: recent Azure and Entra incidents
This isn't the first time Azure's multi-tenant architecture has drawn scrutiny. A Cosmos DB gateway issue disclosed in July 2026 raised concerns about cross-tenant access, though Microsoft said it found no evidence of customer impact and completed a fix across all regions. Separately, Microsoft patched CVE-2025-55241, a critical Entra ID token validation flaw rated CVSS 10.0 that researchers said could have allowed impersonation across tenants entirely.
Neither of those incidents is confirmed to be connected to TheHatman's claims, but together they illustrate why UK firms relying on shared Azure and Entra infrastructure should treat tenant isolation as an ongoing control to verify, not a one-off assumption baked into the platform.
What UK buyers should do now
Given the likely credential-based origin, the priority for UK organisations is auditing identity hygiene across the Azure and Entra estate rather than waiting on a vendor patch. That means confirming MFA coverage on every privileged and service account, reviewing which third-party applications hold directory read permissions, and checking whether infostealer malware has already touched endpoints used to access cloud consoles.
Firms should also revisit how they conduct a thorough risk assessment of supplier and tenant relationships, given how many of the named organisations — TCS, HCL, Hexaware, Kyndryl — sit inside outsourced IT and BPO supply chains that UK enterprises depend on. Where employee directory data could be repurposed for spear-phishing against Global Administrator accounts, it's worth stress-testing detection coverage through a working effective incident response plan rather than discovering gaps mid-incident.
- •Audit MFA enforcement and conditional access policies across all Azure/Entra tenants
- •Review third-party app permissions and remove unused Global Administrator grants
- •Check infostealer exposure via dark-web/credential-monitoring feeds for staff cloud logins
- •Segment and monitor service accounts separately from human identities
- •Reassess supplier risk where outsourcing partners hold access to your tenant
View the data behind this chart
| Access Vector | Risk Level | Key Mitigation | |
|---|---|---|---|
| Infostealer malware | Infostealer malware | High | Endpoint detection |
| Phishing | Phishing | High | Email security + MFA |
| Weak/no MFA | Weak/no MFA | High | Enforce MFA everywhere |
| Overpermissive apps | Overpermissive apps | Medium | App governance review |
| Session cookie theft | Session cookie theft | Medium | Token binding controls |
The bigger picture for cloud buyers
This case lands alongside a busy patch cycle — Microsoft's August 2026 Patch Tuesday round again included a large batch of CVEs across its ecosystem — underscoring that identity risk and patch-management pressure are now running in parallel, not sequentially. UK organisations that treat Azure security as purely a patching exercise will miss the credential-theft route entirely.
For buyers evaluating cloud providers or renewing Azure agreements, the practical takeaway is to separate platform risk from identity risk in contract and audit conversations, and to strengthen their cloud security posture with continuous monitoring rather than point-in-time assessments. Organisations that haven't yet mapped what a breach of this shape would cost should also understand UK data breach costs before deciding how much to invest in prevention versus response.
- 01The Register — Crook hawks millions of records allegedly plundered from corporate Azure tenants · 17 August 2026
- 02The Hacker News — Azure Cosmos DB flaw exposed platform to cross-tenant access · 1 July 2026
- 03The Hacker News — Microsoft patches critical Entra ID flaw (CVE-2025-55241) · 1 September 2025
- 04BleepingComputer — Microsoft Patch Tuesday August 2026 · 11 August 2026
