A dark-web seller put workforce directory exports from nine Azure/Entra tenants on the market and claimed the data came straight out of cloud identity. According to BleepingComputer, the alias TheHatman advertised roughly 3.64 million employee-directory records across McDonald's, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, InterContinental Hotels (IHG), Kyndryl, Gap Inc., Hexaware, and Wyndham Hotels. Only TCS’s public filing names a live login path: password spray and MFA fatigue. TCS and Gap both dispute a recent breach and say the advertised data appears years old.

What TheHatman actually put up for sale

Listings ran from 31 July through 16 August 2026. Coverage landed on 17 August 2026. The seller’s pitch was blunt. One quote captured by BleepingComputer reads: "I'm selling McDonald's Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials." The same framing, dumps pulled from Azure/Entra with compromised credentials, was applied across the set.

Claimed volumes, attributed only to TheHatman via that reporting, break down roughly as McDonald's 1.7M+, TCS 800k+, Vodafone 425k+, HCL 250k+, IHG 185k+, Kyndryl 170k+, Gap 80k+, Hexaware 20k+, and Wyndham 9k+. Those figures sum near the ~3.64 million seller total in the article text. A URL slug that says "36 million" is not the verified count; treat 3.64 million as the figure the reporting actually carried.

Advertised fields were classic directory export material: names, emails, job titles, phone numbers, addresses, employee IDs, and service accounts. Some listings reportedly named Global Administrators. That mix is useful for follow-on social engineering and account targeting even when the rows are not fresh secrets. It is still not proof that every named tenant was live-breached in 2026.

Hudson Rock reviewed samples and judged them highly likely authentic directory exports. The same assessment could not confirm how access was obtained. Infostealer-stolen Microsoft cloud credentials existed for most of the named firms in Hudson Rock’s broader telemetry, yet those infections were not tied to this sale. Session-cookie theft and weak or missing MFA were listed as unproven possibilities, not demonstrated paths for these dumps.

The only named login story: spray, then push spam

Tata Consultancy Services filed an NSE notification that is the sole public window into an attacker-claimed authentication path. According to that filing as reported by BleepingComputer, "The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector." TCS also stated it found "no credible evidence of a breach of TCS systems or customer environments," said the data appears more than four years old, and said it has had strong safeguards against password spray and MFA fatigue for more than two years and found those defenses still effective.

If that claimed chain is taken at face value for analysis, the sequence is a credential-phase failure, not a post-login mystery. Password spray is low-and-slow guessing of common passwords across many accounts so lockouts stay quiet. When a guess hits a still-valid password on a workforce Entra login, the second factor becomes the only gate. MFA fatigue, also called push bombing, is the pattern where the attacker already has the password and floods the user’s phone with approval prompts until one tap goes through. Authentication has not finished when that spam starts. The transferable factor is the approval itself.

That is why user-approvable push is a weak control against this exact story. The cryptography never gets a chance to matter if a human can be worn down into saying yes. Soft OTP and SMS fail for different transfer reasons; push fails here because the second factor is a remote consent the attacker can solicit at scale after a successful spray.

Control in the claimed path What the seller/TCS story implies Why it fails at login
Password on Entra Spray finds a reused or weak password Shared secret is guessable offline of the device
Push approval MFA Prompts spam until one is accepted Factor is transferable consent, not a device-bound proof
Directory read after sign-in Export of people and service-account rows Happens only after an identity is already authenticated

MFA type is known only through that TCS push-fatigue claim. It is unknown at the other named firms.

Gap Inc. pushed back on a fresh corporate compromise. According to a Gap spokesperson quoted via BleepingComputer, preliminary investigation indicated the data was limited in scope, non-sensitive, and several years old, with "no evidence to suggest that our corporate systems have been compromised." Those denials matter. A marketplace listing is not the same thing as a confirmed 2026 tenant takeover at every logo on the slide.

After a session exists, the dump is just export

Lateral movement is not documented. Persistence is not documented. What the actor claims next is simpler and uglier for identity teams: once an already-authenticated cloud identity can read directory objects, exporting names, mailboxes, phones, employee IDs, service accounts, and admin labels is ordinary Graph or admin-console work. That phase is not an MFA problem in the login sense. No second factor undoes a live tenant session that already passed authentication. The interesting security question stays upstream: how did that identity become authenticated in the first place?

SSO and Entra amplify the stakes when the upstream answer is spray-plus-fatigue. One workforce login that completes against the corporate IdP is enough to unlock the directory surface the seller bragged about. Federation and cloud SSO are designed so many apps trust that single proof. When the proof is a password plus a fatigued push, the blast radius is every integrated workload that accepts the resulting session, not just the login page.

What remains unproven is still large. Nobody has shown that these particular dumps came from infostealer cookies harvested after a legitimate login. Nobody has published a verified exfiltration runbook for each tenant. BleepingComputer could not independently verify authenticity of the full corpus. The honest read is narrower: a seller advertised multi-company Azure/Entra employee directories; samples looked like real directory exports to Hudson Rock; the only attacker-claimed live vector on the public record is password spray and MFA fatigue against TCS; TCS and Gap say the material looks old and deny a recent breach.

For defenders, the mechanical lesson does not need every logo confirmed. Password spray still works wherever workforce passwords remain the first factor. Push fatigue still works wherever the second factor is an approvable prompt the attacker can solicit after that password hits. Closing that login-time surface means removing transferable factors from the ceremony, not hoping users never tap Approve under pressure.

For the prevention-side breakdown of closing spray-and-fatigue on workforce Entra logins, read how device-bound Entra login stops password spray and MFA fatigue.

FAQ

Did TheHatman confirm a 2026 breach at every company on the list?

No. TheHatman’s Azure/Entra listings name nine companies and claim directory dumps downloaded with compromised credentials, but TCS and Gap publicly deny a recent compromise and say the advertised data appears years old. Hudson Rock judged samples highly likely authentic directory exports yet could not confirm the access method. Treat the sale as an advertisement with limited corroboration, not as proven live tenant breaches at every named firm.

What attack vector did TCS say the attacker claimed?

According to Tata Consultancy Services’ NSE filing as reported by BleepingComputer, the attacker claimed password spray and MFA fatigue. TCS stated it has had strong safeguards against those techniques for more than two years, found no credible evidence of a breach of TCS systems or customer environments, and said the data appears more than four years old. That claim is the only named login-time path on the public record for this story.

Why would push MFA fail against password spray and fatigue?

Push MFA fails against the claimed TCS path because the second factor is a user-approvable prompt, not a non-transferable device proof. After password spray finds a working password on a workforce Entra login, the attacker can spam approval requests until one is accepted. Authentication is still incomplete when the spam starts, so the weak point is the phishable, fatigueable factor itself.

Were session cookies or infostealers proven for these dumps?

No. Hudson Rock found infostealer-stolen Microsoft cloud credentials for most named firms but could not tie those infections to TheHatman’s access. Session-cookie theft and weak or missing MFA were listed as unproven possibilities. If cookies had been stolen after a legitimate login, that would be a separate post-authentication problem; nobody has demonstrated that path for these listings.

How many records did TheHatman claim, and what fields were listed?

According to BleepingComputer’s coverage of TheHatman’s ads, the seller total is about 3.64 million records across the nine firms, not the "36 million" figure that appears only in a URL slug. Advertised fields included names, emails, titles, phones, addresses, employee IDs, service accounts, and in some listings Global Administrator names. Volumes per brand (for example McDonald's 1.7M+ and TCS 800k+) are seller claims, not independently audited counts.