Home
Blog
What hath Hatman wrought? Huge new data breach or old data recycled?

What hath Hatman wrought? Huge new data breach or old data recycled?

Paul Ducklin
08/18/2026
Share this article:

What happened?

You may have seen the news reports already, almost all of them repeating very similar text to make very similar claims.

Simply put, media feeds say that a data-stealing cybercriminal going by The Hatman has been breaking into lots of big companies hosted on Microsoft Azure by using stolen credentials (phished, perhaps, or guessed, or bought up from other cybercrooks – no one is quite sure), and has stolen huge amounts of sensitive information (or exfiltrated it, in the spy-versus-spy jargon favored by the cybsecurity industry).

Various outlets have made claims that start out with what sounds like certainty, but most if not all have qualified their stories by injecting words such as reportedly, allegedly, and apparently:

“A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials.”

“A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.”

“A cybercriminal is touting on underground marketplaces massive quantities of employee information apparently exfiltrated from Microsoft Azure environments maintained by major corporations.”

“A sprawling Azure data exfiltration campaign is unfolding across the dark web, with a threat actor systematically selling internal employee directories allegedly stolen from some of the world’s largest corporations.”

So far, the companies that Hatman claims to have plundered include: takeway giant McDonald’s; global telecomms operator Vodafone; and Indian IT outsourcing juggernauts Tata Consultancy Services and HCL Technologies.

Employee data from McDonald’s, Hatman insists, includes personally identifiable information (PII) such as employee IDs, phone numbers, home addresses, and more.

We’re assuming that if the stolen PII included super-sensitive data such as SSNs (social security numbers), driving license scans, bank and tax records, and the like, Hatman would have bragged about that.

However, like everyone else who is hedging their bets in telling this story, we’re bound to say that this is merely an assumption.

How did it happen?

What really was stolen, and how dangerous would it be if Hatman sold it on, or dumped it out of spite if no one stepped up to pay for it?

Working out what really was stolen after a data breach is hard enough for attack victims; proving what wasn’t taken can be as good as impossible, especially if the attackers had sufficient access rights that they were able to tamper with access logs and could effectively “rewrite history” after the event.

Tata Consultancy Services (TCS) opened its account by writing to the National Stock Exchange of India to say:

[We have] investigated the matter and [have] not found any credible evidence of a breach of TCS systems or customer environments. The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.

The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. [We have] had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and [we continue] to monitor the environment closely.

That’s an interesting choice of words, with Tata effectively admitting that some of its data has indeed been stolen, albeit not recently, and implying that it’s unimportant because it’s just “basic employee information” and “more than four years old.”

That will be cold comfort, no doubt, to any employees who have worked at Tata for more than four years, especially if they still live at the same address, have the same phone number, and so on.

Data breach news followers will likely recall that the infamous Jaguar Land Rover cyberattack in 2025, which is now said by the Bank of England to have affected the GDP of the UK, and which necessitated a $2 billion government loan to protect Tata-owned JLR and its suppliers, happened in spite of a much-vaunted five-year contract with TCS, signed in 2023 for a range of IT services, including cybersecurity.

What to do?

  • Practice what you will do if you suffer a data breach. If you’re not sure what happened, don’t try to excuse it as unimportant, because anyone affected is likely to disagree with you. It’s OK to be honest and say that you don’t yet know, as long as you provide regular updates as your investigation proceeds. Avoid starting your commentary by saying, “We take your security seriously” if the current evidence suggests you didn’t. Employees and customers are more likely to forgive you and to rebuild their trust if you not only figure out what went wrong, if anything, but also show how you plan to prevent a similar incident from happening again.
  • Remember that stolen data doesn’t automatically lose its value to cybercriminals after a year or two. In the US, for example, acquiring a new SSN is sometimes possible, but not always allowed. SSNs are typically allocated at birth and, for most citizens, last their entire life. People often live in the same property for many years, given that moving house can be an expensive and disruptive upheaval. And other PII, such as your date and place of birth, is by definition immutable.
  • Review the numerous ways that existing online authentication data can be plundered or bypassed by cybercriminals. Obvious examples include: insider threats based on bribery or exortion, where vulnerable staff are lured or threatened to let attackers in; phishing scams that trick users into handing over genuine credentials, often including a 2FA codes (two-factor authentication) that is valid at the time of the attack; 2FA fatigue, where attackers deliberately provoke a stream of “erroneous” login alerts hoping that staff will approve them by mistake or out of frustration; and malware infections such as keyloggers that track users’ keystrokes, mouse movements, and the like, to extract their authentication secrets.
  • Remember that you don’t have to do it all yourself. Stay on top of cyberthreats without distracting staff from your core business. Sign up with SolCyber to do it for you, human style.

If you’re a LinkedIn user and you’re not yet following @SolCyber, do so now to keep up with the delightfully useful Amos The Armadillo’s Almanac series. SolCyber’s lovable mascot Amos provides regular, amusing, and easy-to-digest explanations of cybersecurity jargon, from MiTMs and IDSes to DDoSes and RCEs.

What hath Hatman wrought? Huge new data breach or old data recycled? - SolCyber

Even if you know all the jargon yourself, Amos will help you explain it to colleagues, friends, and family in an unpretentious, unintimidating way.


Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!

What hath Hatman wrought? Huge new data breach or old data recycled? - SolCyber


More About Duck

Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Featured image of steampunk hat by Johnny Briggs via Unsplash.

Paul Ducklin
Paul Ducklin
08/18/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

14707