On 16 August 2026, Hudson Rock published a report on a seller using the handle TheHatman, who is offering what he says are corporate directory exports pulled straight from the Azure / Entra tenants of nine large organisations.

The totals come to more than 3.6 million records. Almost none of it has been confirmed by anybody.

What is being claimed

OrganisationRecords claimed
McDonald's1,700,000+
Tata Consultancy Services800,000+
Vodafone425,000+
HCL Technologies250,000+
InterContinental Hotels Group185,000+
Kyndryl170,000+
Gap Inc.80,000+
Hexaware20,000+
Wyndham Hotels9,000+

BleepingComputer puts the listing activity between 31 July and 16 August 2026.

The described contents are what an Entra directory export actually holds: employee names, corporate email addresses, phone numbers, postal addresses, employee IDs, job titles and departments — plus manager and reporting relationships, group memberships, service accounts, and records identifying Global Administrator accounts.

What the seller says, and what the researchers say

TheHatman's account has been consistent: compromised credentials. In the forum posts, the specific claim is password spraying and MFA fatigue.

Hudson Rock's assessment is narrower and more useful. On the data, the samples reviewed look consistent with genuine directory exports — real corporate email addresses, the field structures you would expect. On the intrusion, the firm says the access vector and exfiltration method remain unknown.

It did find something adjacent: compromised Azure credentials tied to infostealer infections on machines traced to employees at TCS, Gap, HCL and Kyndryl. That is a real finding and it is not the same finding. An infostealer log containing a corporate Azure credential shows a credential was stolen. It does not show that credential was used to export a tenant directory.

This is the distinction the whole story turns on, and it is the same one we drew over the thirty-minutes-to-exploit claim: the artefact is real, the chain from artefact to outcome is asserted.

What the companies say

TCS investigated and reports no credible evidence of a breach, describing the data as at least four years old and limited to basic information.

Gap Inc. says it found no evidence its corporate systems were compromised, and describes the data as non-sensitive and several years old.

The others have declined to comment or have not responded.

All of it can be true at once

There is no contradiction to resolve here, which is what makes it worth writing down.

A directory export taken four years ago is genuine data. A company examining its logs today can honestly find no evidence of a recent breach. Records that are individually mundane can be structurally valuable. A seller can hold real data and still be lying about how he got it — sellers routinely inflate the intrusion because "I bought an old dump" prices worse than "I am inside your tenant".

The one claim that has been independently checked is the shape of the data. Everything else — the vector, the recency, whether any single tenant was accessed at all — has not been.

Why an old directory is still worth something

Dismissing this as non-sensitive misses what the file is for.

An attacker holding a corporate directory does not need passwords. They get the org chart: who reports to whom, which names carry Global Administrator, which accounts are service accounts, which groups exist and who is in them.

That is the entire input to a convincing pretext. It is what makes the call from "IT" name the right manager, and the reset request land on the right helpdesk queue. We have written about UNC6671 talking targets through enrolling an attacker's passkey and STAC4749 running the same play through Teams. Neither needed a password. Both needed to sound like they belonged.

Reporting lines age slowly. A four-year-old org chart at a company with low churn is mostly still correct, and where it is wrong it is wrong in ways the target cannot easily tell from a phone call.

The India angle

Three of the nine — TCS, HCL and Hexaware — are Indian IT services firms, and between them account for more than a million of the claimed records.

For Indian companies this now sits inside a regulatory clock as well as a security one. The DPDP Act obligations we set out here carry breach-notification duties, and "we found no credible evidence" is a defensible position only for as long as it survives contact with the logs. TCS has stated its finding publicly and early, which is the right instinct.

What to do

  • Search your infostealer exposure, not your breach logs. The Hudson Rock finding is about employee machines, not tenant intrusions. If a staff device was infected, assume the Azure session cookies and saved credentials on it are gone — the same mechanism as AmnesiaStealer's session hijacking.
  • Audit who can read the directory. In a default Entra tenant, ordinary authenticated users can enumerate far more than most administrators assume. Restricting that is a configuration change, not a project.
  • Treat Global Administrator names as sensitive. They are a target list. Keep them few, named, and separate from day-to-day accounts.
  • Assume the org chart is public. Then check whether any of your verification processes rely on it being private. Helpdesk identity checks that ask for a manager's name fail this test immediately.
  • Kill password spray and MFA fatigue as viable routes. Number matching, sign-in risk policies and lockout thresholds — regardless of whether they were used here, they are what the claim describes. Related: the passkey attack paths in Entra.

What is not established

  • Authenticity. No independent authentication of the datasets had been published at the time of writing. Hudson Rock's review speaks to structure, not provenance.
  • The access vector. Hudson Rock says it is unknown. The password-spray and MFA-fatigue claim is the seller's.
  • Whether any tenant was actually accessed. An export can be four years old and can have left by other means entirely.
  • Microsoft's position. No statement from Microsoft has been reported.
  • The count. Nine organisations are named and the per-company figures sum to roughly 3.64 million; at least one outlet describes it as eight Fortune 500 companies. We use nine, because that is what the itemised list contains.