Threat actors are allegedly selling millions of employee records stolen from Microsoft Azure environments belonging to several Fortune 500 companies. The cybercriminals claim they gained access using compromised credentials.
Beginning July 31, an individual using the alias “TheHatman” advertised data dumps allegedly taken from organizations including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services (TCS), HCL Technologies, InterContinental Hotels Group (IHG), and Kyndryl.
The threat actor claimed the databases contain approximately 3.64 million records. The latest listing, published Sunday, allegedly includes more than 1.7 million McDonald’s employee records.
“I am selling McDonald’s Corporation internal employee dumps that I downloaded directly from my Azure tenant using compromised credentials,” TheHatman claimed in the listing.
According to the threat actor, the alleged McDonald’s data includes employee names, identification numbers, email addresses, job titles, phone numbers, physical addresses, service accounts, and other tenant account information.

Source: BleepingComputer
The second-largest database advertised was allegedly stolen from Tata Consultancy Services. The cybercriminals claimed the Azure data dump contains more than 800,000 employee records and was “downloaded directly from an Azure tenant using compromised credentials.”
However, Tata Consultancy Services told the National Stock Exchange of India that its investigation found no “credible evidence of a breach of the TCS system or customer environment.”
The company said the information appears to be at least four years old and contains only basic employee details.
“The attackers claim to have used password spraying and multi-factor authentication (MFA) fatigue as attack vectors. We have had strong protections against such techniques for over two years,” Tata said.
Tata added that a review of its security controls found that its defenses remained effective.
A Gap Inc. spokesperson also told BleepingComputer that the company found no evidence of a security breach. The company said the advertised information is not sensitive and dates back several years.
“Based on our preliminary investigation, the data in question is limited in scope, non-sensitive, and dates back several years. Specifically, there is no evidence to suggest that our corporate systems were compromised,” a Gap Inc. representative said.
Between July 31 and August 16, TheHatman advertised alleged Azure or Microsoft Entra data dumps linked to the following organizations:
| Company | Estimated size | Database type | Alleged data |
| McDonald’s | More than 1.7 million records | Azure internal employee database | Names, email addresses, job titles, phone numbers, and addresses |
| Gap Inc. | More than 80,000 records | Azure internal employee database | Names, email addresses, job titles, phone numbers, and addresses |
| Vodafone | More than 425,000 records | Azure internal employee database | Names, email addresses, job titles, phone numbers, and addresses |
| Tata Consultancy Services | More than 800,000 records | Azure database dump | Names, email addresses, job titles, phone numbers, and addresses |
| HCL Technologies | More than 250,000 records | Azure database dump | Names, email addresses, job titles, phone numbers, and addresses |
| InterContinental Hotels Group | More than 185,000 records | Azure database dump | Names, email addresses, job titles, phone numbers, and addresses |
| Wyndham Hotels | More than 9,000 records | Azure/Entra database dump | Names, email addresses, job titles, phone numbers, and addresses |
| Hexaware | More than 20,000 records | Azure/Entra database dump | Names, email addresses, employee IDs, phone numbers, and addresses |
| Kyndryl | More than 170,000 records | Azure/Entra database dump | Employee accounts, service accounts, and other tenant account records |
TheHatman also shared sample files from each advertised database so potential buyers could review the alleged information before purchasing.
Cybercrime intelligence company Hudson Rock analyzed the alleged leak and found that the samples used a consistent data structure containing “basic corporate directory attributes” and active domain and tenant-specific .onmicrosoft.com structures.
The samples also reportedly contain service account and global administrator names. Such information could be used to support social engineering, phishing, and targeted spear-phishing campaigns.
Hudson Rock said it is highly confident that the data is genuine, although the alleged method used to access and exfiltrate the information remains unknown. BleepingComputer has not independently verified the authenticity of the databases.
BleepingComputer contacted the publicly traded companies regarding the alleged Azure data breach but had not received additional comments by the time of publication.
Security controls can weaken after attackers obtain valid credentials. Blue Report 2026 examines what happens after initial access and measures defense techniques across 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




