Skip to main content
Emerging ThreatsData Breaches

Azure Breach Exposes 3.6 Million Records from Top Companies

A lone laptop sits on a table in an empty corporate office lobby or data center.

“I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” wrote a threat actor using the alias “TheHatman,” advertising large employee databases allegedly taken from Microsoft Azure tenants of several major companies.

TheHatman’s claims and timeline

Starting July 31, posts from TheHatman began offering databases purportedly exfiltrated from corporate Azure tenants. The seller claims a total of 3.64 million records across multiple companies, with the most recent posting containing an alleged 1.7 million employee records from McDonald’s. The second-largest advertised dump is an Azure export claimed to contain more than 800,000 employee records from Tata Consultancy Services.

Other organizations named in the listings include Gap Inc., Vodafone, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. For each advertised database, TheHatman provided a sample database for potential buyers to verify the data.

Companies named: statements from Tata Consultancy Services and Gap Inc.

Tata Consultancy Services (Tata) told the National Stock Exchange of India that it “investigated the alleged breach and found no ‘credible evidence of a breach of TCS systems or customer environments.’” Tata added that the details “appear to be at least four years old and include only basic employee information.” The company also said, “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years,” and that it had “reviewed its defenses and found that they remain effective.”

In a statement to BleepingComputer, a Gap Inc. spokesperson said the company “found no evidence of a breach. Additionally, the advertised data is not sensitive in nature and dated back to several years ago.” The spokesperson added, “Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised.”

BleepingComputer contacted the listed companies about the potential breach but had not received comments by the time of publication.

Hudson Rock’s analysis: structure, domains, and administrative accounts

Cybercrime intelligence firm Hudson Rock analyzed the leaked samples and reported that they contain “foundational corporate directory attributes” alongside a clear data structure. The firm highlighted the presence of “active domains and tenant-specific .onmicrosoft.com structures,” and said the dumps include service accounts and the names of global administrators.

Hudson Rock said these elements could “facilitate social engineering and spearphishing attacks.” The company expressed high confidence that the data are authentic, but noted that the access vector and exfiltration method remain unknown. BleepingComputer said it was not able to independently verify the authenticity of the dumps.

Claims of password spray and MFA fatigue; prevention context from the Blue Report 2026

TheHatman stated the attacker used password spray and Multi-Factor Authentication fatigue as the access techniques. Tata’s notification to the stock exchange cited those specific techniques and asserted the company has had safeguards against them for more than two years.

The source material also quoted a broader defensive observation: “Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.” The Blue Report 2026 was cited as measuring “defenses technique by technique across 338 million simulations run in customer production environments,” underscoring the difference between stopping initial compromise and limiting damage after credential misuse.

What this means for technologists and security teams, affected enterprises, and employees

  • Technologists and security teams: Hudson Rock’s finding that the dumps include service accounts and global administrator names raises the specific risk of targeted social engineering and spearphishing campaigns against privileged accounts.
  • Affected enterprises and procurement leaders: Tata and Gap have publicly described the advertised data as dated and non-sensitive or old; the McDonald’s claim and other listings remain allegations from TheHatman that, per Hudson Rock, appear structured like corporate directories but lack a confirmed access vector.
  • Employees and end users: TheHatman said the information includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records — categories that, if accurate, can increase exposure to targeted outreach and impersonation attempts.

The record presented so far is precise about what was offered and what some firms have said in response, but crucial forensic questions remain: the source materials make clear Hudson Rock has “high confidence that the data is authentic,” yet the “access vector and exfiltration method remain unknown,” and BleepingComputer “has not been able to independently verify” the dumps. That gap — whether these are old, aggregated directory exports or evidence of recent tenant compromise — is the determinative detail for defenders and investigators.

Original reporting on BleepingComputer