Hudson Rock: TheHatman selling Azure data from McDonald's, TCS, Vodafone
This digest was compiled by AI from multiple sources — links to the originals are below.

A threat actor using the alias TheHatman is selling data allegedly stolen from the Azure/Entra tenants of McDonald's, Tata Consultancy Services, Vodafone, and other Fortune 500 firms, Hudson Rock reports. The advertised datasets include employee directories with names, emails, phone numbers, job titles, service accounts, and global admin identities, exposing personnel to spear-phishing and business email compromise. While no Azure zero-day flaw has been confirmed, Hudson Rock links the access to credentials compromised in a targeted infostealer campaign.
Key Facts
- TheHatman's advertised datasets include McDonald's with over 1.7 million records, TCS with 800,000, Vodafone with 425,000, HCL Technologies with 250,000, and IHG with 185,000.
- Additional listings cover Kyndryl with 170,000 records, Gap with 80,000, Hexaware Technologies with 20,000, and Wyndham Hotels with 9,000.
- The leaked data includes employee names, corporate emails, phone numbers, addresses, job titles, manager details, service accounts, and global admin identities.
- Hudson Rock identified stolen credentials linked to most victim organizations and attributes the access to a targeted infostealer campaign, while no Azure zero-day flaw has been confirmed.
- The exposure of service accounts and global admin names provides a roadmap for spear-phishing and privilege escalation.
Advertised Datasets
The threat actor TheHatman has listed data allegedly taken from the Azure and Entra tenants of at least nine Fortune 500 firms, including McDonald's, TCS, Vodafone, HCL Technologies, IHG, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels. The largest dataset is McDonald's, with over 1.7 million records, followed by TCS at 800,000, Vodafone at 425,000, HCL Technologies at 250,000, and IHG at 185,000. Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels are also represented in the listings with 170,000, 80,000, 20,000, and 9,000 records respectively. The leaked records consistently include corporate directory attributes such as employee names, corporate email addresses, physical addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, and highly privileged account records. Hudson Rock assessed the dumps as legitimate based on internal employee directories, identified email addresses, and field names matching Azure directory exports.
Access Method and Impact
Hudson Rock identified stolen credentials linked to most of the at least nine affected organizations and attributes the access to a targeted infostealer campaign. No Azure zero-day exploit has been confirmed; the listings point to access through compromised credentials rather than a vulnerability in Azure itself. The exposure of service accounts and global admin names provides a direct roadmap for social engineering, spear-phishing, and privilege escalation attacks. The stolen data lets attackers map internal reporting structures and high-value targets and launch convincing spear-phishing and business email compromise campaigns. The campaign impacts global enterprises across IT services, hospitality, telecommunications, retail, and logistics.
2 sources
Hudson Rock: TheHatman selling Azure data from McDonald's, TCS, Vodafone



