3.6 Million Employee Records. Nine Companies. One Stolen Password. Here's What the Azure Heist Means for Your Business.
A threat actor called TheHatman just sold the internal employee directories of McDonald's, Vodafone, and seven other major companies — pulled directly from their Azure environments using compromised credentials. Here's what every business leader needs to know.
A threat actor going by "TheHatman" just sold the internal employee directories of McDonald's, Vodafone, Tata Consultancy Services, InterContinental Hotels, Gap, Kyndryl, and three other major corporations — 3.64 million records in total — all pulled directly from their Microsoft Azure and Entra ID environments using compromised credentials.
The data is sitting on cybercrime forums right now. It includes full names, corporate email addresses, job titles, phone numbers, physical addresses, employee IDs, direct-report relationships, organizational charts, service accounts, and in some cases, the names of accounts holding Global Administrator privileges.
Nobody broke through a firewall. Nobody exploited a zero-day vulnerability. Somebody stole a credential — and walked right through the front door.
What Happened: A Credential-First Attack at Scale
Hudson Rock, the cybersecurity intelligence firm that analyzed the leaked data, confirmed that the records appear highly authentic. The corporate email addresses, field structures, and tenant-specific Microsoft domain formats all match a legitimate Azure directory export.
How did TheHatman get in? The exact method isn't confirmed, but Hudson Rock's analysis points to a short list of likely vectors: infostealer malware that harvested session tokens from infected employee devices, phishing campaigns that captured administrative credentials, MFA fatigue attacks that bombarded employees with authentication requests until they clicked "approve" just to make it stop, or a third-party application integrated into these Azure tenants that had excessive read permissions it never should have had.
The common thread: none of these attack methods require a sophisticated technical exploit. They require a stolen password and a door that wasn't locked properly.
Why This Should Concern You — Even If You're Not McDonald's
Here's the part that matters for every business leader, not just the nine companies currently named: this attack succeeded because it exploited the gap between how IT thinks access works and how it actually works in a real enterprise.
Your Microsoft Azure or Entra ID environment almost certainly contains a similar internal directory — a structured database of every employee, their role, their contact information, their reporting relationships, and their system access. That directory is enormously valuable, not just for the data itself, but for what it enables.
An attacker with your employee directory can do a lot of damage without ever touching another one of your systems. They can craft hyper-personalized spear-phishing emails that reference an employee's actual manager by name, their actual job title, and their actual department. They can impersonate IT or HR in a voice call because they already know exactly who works where. They can identify which accounts hold privileged access — the Global Administrators and service accounts — and target those specifically. They can map your entire organizational structure and social-engineer the right people at exactly the right moment.
In the security world, this is called "reconnaissance at scale." TheHatman handed whoever buys this data everything they'd need to run a highly targeted attack campaign against thousands of organizations, customized for each one.
The Three Questions Every Business Leader Should Ask Right Now
You don't need to be a cybersecurity expert to ask these questions to your IT team or managed service provider. You need to ask them this week.
One: How would you know if someone pulled our Azure directory?
Most organizations have robust protections around their applications and endpoints, but far less visibility into what's happening at the identity and directory layer. Can your team tell you whether an unusual export or read operation happened against your Azure/Entra environment in the last 30, 60, or 90 days? If the answer is "we'd have to check" or "probably not," that's a gap.
This isn't about blame — it's about understanding your current visibility. Microsoft Entra ID does generate audit logs for directory read operations, permission changes, and bulk exports. Those logs need to be actively monitored, not just available.
Two: How many third-party applications have read access to our employee directory — and do they all still need it?
Every SaaS tool your organization has connected to Microsoft 365 or Azure AD over the years has been granted some level of permission. Marketing automation platforms, HR tools, project management software, collaboration apps — many of them request directory read access as part of their setup, and most organizations grant it without a second thought.
Hudson Rock specifically flagged third-party API abuse as a possible intrusion vector in this campaign. The question isn't whether your connected apps are trustworthy today — it's whether their permission levels are appropriate, whether they're still actively used, and whether any of them have been compromised by their own vendors without your knowledge.
Three: What's our MFA strategy — and is it actually protecting us?
MFA is not a finished security project. It's a control that requires ongoing configuration and monitoring. MFA fatigue attacks — where attackers spam authentication requests until a tired or confused employee hits "approve" — are now a documented, confirmed attack vector used in major breaches. Simple push-notification MFA is vulnerable to this. Number-matching, hardware keys, and phishing-resistant MFA methods are not.
If your MFA implementation is still based on push notifications that just ask "Is this you?", it's worth asking your team whether you've migrated to something more resistant.
What This Really Represents
The TheHatman campaign isn't remarkable because of the technical sophistication involved — it's remarkable because of how simple it was. The attacker didn't need a nation-state budget or a custom exploit. They needed a stolen credential and access to a cloud environment where directory read permissions were insufficiently constrained.
That combination — compromised credentials plus excessive permissions plus insufficient monitoring — is the single most common root cause across the major breaches we've seen in 2026. It was present in the Accenture breach. It was present in the EY breach. It was present in the Amgen cloud vendor attack. The tools change. The playbook doesn't.
Your employee directory isn't just an HR convenience. In the wrong hands, it's a targeting package — a map your adversaries can use to social-engineer your people, compromise your accounts, and breach your business one conversation at a time.
The question isn't whether your organization has a directory that would be valuable to an attacker. Every organization does. The question is whether you'd know it was being read, and whether the conditions that allowed TheHatman's campaign to work are present in your environment right now.
If you're not sure, that's the starting point. TrustPoint Cyber can help you assess your identity security posture, review your Azure/Entra permissions, and build the monitoring controls that would surface this kind of activity before it ends up on a cybercrime forum.
The next step is a conversation. Let's have it before someone else does.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.