you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / market watch
27 August 2026 market watch 4 min read

Solo vendor dumps 3.6 million Azure employee records: nine corporate tenants hit in two weeks

Between July 31 and August 16, 2026, a lone actor using the handle TheHatman published a series of data dumps on cybercrime forums that security researchers now believe came straight out of corporate Microsoft Entra ID (formerly Azure AD) tenants. In under three weeks, approximately 3.64 million employee-directory records from nine major companies surfaced for sale, all allegedly pulled through the same technique: logging into enterprise cloud identity portals with credentials harvested by infostealer malware.

Who got hit and how big are the dumps

The largest single cache belongs to McDonald's, at roughly 1.7 million records. Tata Consultancy Services follows with around 800,000, then Vodafone at approximately 425,000 and HCL Technologies at about 250,000. Smaller sets were attributed to InterContinental Hotels Group, Kyndryl, Gap, Hexaware, and Wyndham. According to BleepingComputer's reporting on the claims, the listings appeared one after another on multiple forums over the seventeen-day window, suggesting a deliberate sales campaign rather than an opportunistic leak. The affected organizations span retail, hospitality, fast food, telecom, and IT services — sectors with enormous workforces and sprawling contractor networks. That mix matters, because employee directories are not just names and emails; they are organizational charts.

Why analysts think the data is real

Threat intelligence firm Hudson Rock examined the samples and concluded the dumps are highly likely authentic. Two details drove that assessment. First, the field structure matches genuine Azure directory exports — the exact column layout produced when someone queries tenant user objects, including attributes most outsiders would never guess to fabricate. Second, the records include entries that should never appear in anything public: internal service accounts, machine identities, and the names of Global Admins, the highest-privilege roles in a Microsoft 365 environment. That last point is what elevates this from an embarrassing contact-list leak to something more dangerous. A Global Admin name paired with a working email format gives attackers a precise target list for phishing, MFA fatigue prompts, and help-desk social engineering. Service account identifiers, meanwhile, often map to systems where password rotation is lax.

The exfiltration playbook

Hudson Rock's analysis frames the campaign as a textbook case of infostealer-to-tenant escalation. Credentials lifted from individual employees' infected machines were replayed against the companies' Entra sign-in pages, and valid sessions were used to enumerate directory contents in bulk. No exploit, no zero-day — just stolen passwords and session tokens doing exactly what they were issued to do. This mirrors the pattern we described in how old dump credentials keep enabling account takeovers: yesterday's commodity logs become today's enterprise breach. The Register's coverage adds context on the seller himself, noting that TheHatman operated alone rather than as part of a known crew and priced the datasets for forum buyers directly. A solo operator moving this much volume underscores how low the barrier has become: one patient criminal with access to stealer-log inventory can strip directories from multiple Fortune-scale tenants without touching a single endpoint inside them.

TCS pushes back

Not every named company agrees on what happened. TCS filed a statement with the Bombay Stock Exchange denying a credible breach and asserting that the data being circulated is more than four years old. That framing matters commercially — disclosure obligations and reputational exposure both hinge on whether an incident counts as current. But age does not equal harmlessness. Directory exports from 2022 still contain accurate reporting lines for many long-tenured staff, still reveal naming conventions and admin aliases, and still feed convincing pretexts for social engineering campaigns run against the company today. The dispute also highlights a recurring pattern in these cases: vendors selling recycled or partially refreshed data under fresh branding, and victims contesting freshness to limit legal exposure. Both things can be true at once — old data, new harm.

What defenders should take from it

For anyone running an Entra ID or Azure tenant, the checklist is familiar but newly urgent. Conditional access policies should assume credential theft as the default state of the world, not the exception. Directory enumeration deserves monitoring just like sign-in failures do — a single account quietly exporting hundreds of thousands of user objects is a loud signal if anyone is listening for it. Privileged role membership should be minimized and obfuscated where possible, since Global Admin names are now sitting in a forum archive somewhere. And service accounts need dedicated, rotated, hardware-bound credentials instead of shared passwords inherited from a decade ago. The broader lesson rhymes with everything else happening in the credential economy. Infostealers feed the front of the funnel, initial access brokers and solo sellers monetize the middle, and the downstream cost lands on enterprises that treated directory data as harmless metadata. Three point six million records later, that assumption looks harder to defend.

more notes

all news ›