A threat actor named TheHatman is conducting a large-scale data exfiltration and sales campaign targeting Fortune 500 companies. The actor is advertising massive internal employee databases from major corporations like McDonald's, Vodafone, and Kyndryl on dark web forums. TheHatman claims the data was exfiltrated directly from the victims' Microsoft Azure and Entra ID tenants. The most probable attack vector is the use of compromised credentials, likely harvested via info-stealer malware or phishing campaigns, to gain administrative access to the cloud environments. The stolen data, consisting of extensive employee directories, poses a significant risk for follow-on social engineering and spear-phishing attacks.
Over the past week, TheHatman has been systematically listing data dumps from high-profile global enterprises for sale. The actor's claims of accessing Azure tenants directly suggest a focus on cloud-based identity and data stores. Security researchers have found evidence supporting the credential compromise theory, including examples of Azure Active Directory credentials for employees at major firms appearing in info-stealer logs. This indicates that the campaign is likely the result of attackers operationalizing previously stolen credentials on a massive scale, rather than exploiting a zero-day flaw in Microsoft's cloud platform. The actor's ability to extract data from multiple, disparate organizations suggests an automated and systematic approach to compromising and exfiltrating data from cloud tenants.
The campaign appears to leverage compromised credentials to access and exfiltrate data from cloud environments.
Likely Attack Chain:
T1555 - Credentials from Password Stores) or sophisticated phishing attacks (T1566 - Phishing). These campaigns may have yielded credentials for users with privileged access to the Azure environment.T1078.004 - Cloud Accounts.T1530 - Data from Cloud Storage Object.The exfiltration of complete internal employee directories is highly valuable for malicious actors. This data serves as a blueprint for an organization's structure and personnel. It enables highly targeted and convincing spear-phishing, business email compromise (BEC), and social engineering attacks. For example, an attacker could use the directory to identify finance department employees and impersonate a senior executive to request a fraudulent wire transfer. The breach also exposes employees to personal risks of identity theft and harassment. For the affected companies, it represents a significant security failure in their cloud environment, leading to reputational damage and the high cost of responding to subsequent attacks.
No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.
Security teams managing Azure/Entra ID environments should hunt for the following patterns:
log_sourceEntra ID Sign-in Logslog_sourceEntra ID Audit LogsExport-AzureADUser or bulk downloads of user directories. Also, monitor for the creation of new applications with high-privilege API permissions (e.g., User.Read.All, Directory.Read.All).command_line_patternnetwork_traffic_patternAnomalous access to graph.microsoft.comDomain Account Monitoring (D3-DAM).M1032 - Multi-factor Authentication.Directory.Read.All unless absolutely necessary and heavily monitored. This aligns with M1026 - Privileged Account Management.Enforce phishing-resistant MFA for all cloud accounts, especially those with administrative privileges, to neutralize the threat of stolen credentials.
Mapped D3FEND Techniques:
Apply the principle of least privilege to all Azure/Entra ID accounts. Avoid standing administrative access and use Privileged Identity Management (PIM) for just-in-time access.
Mapped D3FEND Techniques:

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.