Bottom line: An actor known as "theHatman" is allegedly offering for sale 3.6 million corporate data records originating from Microsoft Entra tenants of McDonald's, Vodafone, TCS, HCL, IHG and other companies, with no confirmation of the compromise available.
A cybercriminal using the alias "theHatman" is offering around 3.6 million corporate data records allegedly originating from Microsoft Entra tenants. Those said to be affected include McDonald's, Gap Inc., Vodafone, Kyndryl, Tata Consultancy Services, HCL Technologies and InterContinental Hotels Group (IHG).
According to the source, an actor under the alias “theHatman” is offering a dataset of around 3.6 million entries in relevant underground forums, allegedly stolen from Microsoft Entra ID tenants (formerly Azure Active Directory) belonging to several well-known companies. Those named as affected include McDonald’s, Gap Inc., Vodafone, Kyndryl, Tata Consultancy Services (TCS), HCL Technologies and InterContinental Hotels Group (IHG). According to the source, details on the exact nature of the data contained — such as whether it involves user accounts, credentials, configuration information or metadata — as well as the timing and vector of the alleged access are not available.
As a central identity service in many enterprise environments, Microsoft Entra ID forms the foundation for authentication, access control and single sign-on across numerous cloud and on-premises applications. Should the claim of successful access to such tenant data be confirmed, this would pose a risk extending beyond individual accounts: compromised identity data can serve as a starting point for lateral movement, business email compromise, or further attacks on downstream systems and partner companies. Given the affected parties named — spanning food service, retail, telecommunications, IT services and hospitality — the potential reach would be correspondingly broad.
For security leaders, verification is the primary concern at this stage: offers on underground forums are not automatically equivalent to a confirmed compromise, as aggregation from older leaks, exaggeration of scope, or deliberately false claims to boost a seller’s reputation are not uncommon. Until confirmation is provided by the affected companies or through independent analysis, heightened vigilance toward unusual login attempts, a review of Conditional Access policies, and monitoring for signs of credential stuffing or account takeover attempts within one’s own organization’s and its supply chain’s Entra ID environments is nonetheless advisable.
Source: borncity.com · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.