Overview
- A threat actor using the alias “TheHatman” has advertised roughly 3.64 million employee records from multiple companies, with posts and sample dumps posted between July 31 and August 16.
- Cybercrime intelligence firm Hudson Rock analyzed samples and found field names and structures consistent with Azure/Entra directory exports, and judged the material likely authentic.
- The advertised data includes names, corporate emails, job titles, employee IDs, manager relationships, group memberships, service accounts, and some global admin names.
- Several named companies including Tata Consultancy Services and Gap have said they found no credible evidence of a recent systems breach and that some records appear to be dated or non‑sensitive.
- Analysts say the likely exfiltration path is credential compromise from infostealer malware or credential abuse rather than a platform zero day, and they warn the leaked attributes raise near‑term risks of spear‑phishing, business email compromise, and privilege‑escalation attacks.