ThreatPaper
Data BreachDarknet & Illicit MarketsMedium

TCS employee-directory leak claim: 800,000 records advertised by 'TheHatman', company finds no breach

By Sethu Satheesh · 6 Oct 2026 · 13 min read

Threat Actor: Unknown / self-identified as TheHatman · Target: Tata Consultancy Services (TCS)

Source: www.bseindia.com


Executive Summary

In early August 2026 a threat actor using the forum handle "TheHatman" advertised employee-directory data said to have been exfiltrated from the Microsoft Azure and Entra ID tenants of nine large enterprises. The listings were surfaced publicly on 10 August 2026 by the South Korean cyber-intelligence firm S2W, whose @S2W_DailyThreat account reported that roughly 800,000 Tata Consultancy Services (TCS) employee records were among the data offered for sale, with a sample of about 6,000 records attached to the listing.1 Security outlets and the infostealer-intelligence firm Hudson Rock subsequently documented a wider campaign of about 3.6 million records spanning McDonald's (~1.7 million), TCS (~800,000), Vodafone (~425,000), HCL Technologies (~250,000), InterContinental Hotels Group (~185,000), Kyndryl, Gap Inc., Hexaware Technologies and Wyndham.234

The data in question is a corporate directory, not source code and not a credential dump. The records reported across the campaign consist of names, employee IDs, corporate email addresses, job titles and departments, phone numbers, postal and office addresses, manager and reporting relationships, group memberships, service-account entries and, in some tenants, the names of Global Administrator accounts.34 Researchers assess that such credentials as were involved were used as a means of access, not themselves published; nothing in the public reporting points to a vulnerability in Microsoft's platform.23

On the same day the claim surfaced, TCS filed a Regulation 30 intimation (reference TCS/SE/72/2026-27) with the National Stock Exchange of India and BSE. The company said it had "not found any credible evidence of a breach of TCS systems or customer environments," that the referenced information "appears to be more than four years old and limited to basic employee information," and that "there is no indication that customer data, customer systems, or TCS operational systems have been impacted."5 TCS further noted that the attacker claimed to have used password spray and multi-factor-authentication (MFA) fatigue, and stated it has "had strong safeguards in place against such techniques for more than two years."5

This paper is therefore a claim-versus-denial record. The actor's listing concretely exists and was analysed by named researchers; TCS's denial is a first-party regulatory filing. What remains unverified is the core question: whether any genuine, current TCS data was exfiltrated from TCS systems at all. Hudson Rock judged samples "highly likely authentic" while stating it was "not conclusive how this campaign is being carried out"; BleepingComputer and The Register could not independently confirm the data.263 As of 6 October 2026 no CERT-In advisory, regulator confirmation, or further TCS filing on the matter has been located. Readers should also not confuse this August 2026 directory-data claim with the separate 2025 incident in which the "Scattered Spider" cluster was reported to have breached Marks & Spencer using credentials associated with a third-party TCS contractor; the two are unrelated.

Verification of Claims

  1. Claim: TCS received threat-intelligence alerts and filed a regulatory intimation on 10 August 2026 stating it found no credible evidence of a breach. → Verified → TCS's own Regulation 30 filing (TCS/SE/72/2026-27), digitally signed by Company Secretary Yashaswin Sheth on 10 August 2026, states the company "has not found any credible evidence of a breach of TCS systems or customer environments."5

  2. Claim: A forum actor "TheHatman" advertised roughly 800,000 TCS employee-directory records within a ~3.6 million-record, nine-company Azure/Entra campaign. → Partially verified → S2W first reported the TCS listing on X; Hudson Rock, The Register, SecurityWeek and BleepingComputer document the wider campaign and sample data.12346 The listing's existence is established; the full dataset, its exact size, and its origin in a TCS compromise are not independently confirmed.

  3. Claim: The advertised samples are "highly likely authentic" Azure/Entra directory exports. → Partially verified (reported as an assessment) → This is Hudson Rock's stated assessment, based on corporate email structures and field names consistent with Azure directory exports; the same firm said it was "not conclusive how this campaign is being carried out."2 Authenticity of a sample is not confirmation of a current TCS breach, which TCS disputes.5

  4. Claim: The referenced data is "more than four years old" and limited to basic employee information. → Partially verified (first-party assertion) → This is TCS's assertion in its filing; no independent party has dated the data.5 Gap Inc. made a comparable statement that its data was "limited in scope, non-sensitive and dated back to several years ago."6

  5. Claim: The intrusion used password spray and MFA fatigue. → Unverified / conflicting → TCS relays this as the attacker's own claim; Hudson Rock instead attributes access to credentials harvested by infostealer infections.52 Neither account has been forensically confirmed for TCS specifically.

  6. Claim: No Indian government body has confirmed the leak or issued an advisory. → Verified by absence (as of 6 October 2026) → No CERT-In advisory, vulnerability note, or incident note referencing this campaign or TCS was located, and TCS's exchange-filing history shows no further disclosure on the matter after 10 August 2026.78

Timeline

Date Actor Event Source
July 31 – August 16, 2026 "TheHatman" Datasets attributed to nine enterprises advertised for sale on cybercrime forums 23
August 10, 2026 S2W @S2W_DailyThreat publicises a listing claiming ~800,000 TCS employee records, with a ~6,000-record sample 1
August 10, 2026 TCS Files Regulation 30 intimation (TCS/SE/72/2026-27) with NSE and BSE; reports no credible evidence of a breach 5
August 10, 2026 Reuters Reports TCS's exchange disclosure that customer data was not impacted 9
August 16, 2026 Hudson Rock Publishes analysis assessing samples "highly likely authentic" and linking access to infostealer-stolen credentials 2
August 17, 2026 The Register / SecurityWeek / BleepingComputer Report the ~3.6 million-record campaign; note the data could not be independently verified 346
As of October 6, 2026 CERT-In / TCS No CERT-In advisory and no further TCS filing on the matter located 78

Incident Anatomy

TCS states that no breach of its systems occurred, so the sequence below is the mechanism as claimed by the actor and as reconstructed by Hudson Rock from the advertised data — not a confirmed intrusion of TCS. It is presented at a defender's level of detail.

Initial access (claimed)

Two incompatible accounts exist. The actor, as relayed in TCS's filing, claimed to have used password spraying and MFA-fatigue prompt bombing to obtain a foothold.5 Hudson Rock, examining the broader campaign, instead attributed access to valid credentials harvested by infostealer malware running on endpoints — in at least some cases outside the affected organisations' managed estate — and noted the precise entry point remained unconfirmed.23 Both accounts describe abuse of legitimate identities rather than exploitation of an Azure/Entra platform flaw.2

Directory enumeration and export (claimed)

With an authenticated identity, the actor is said to have enumerated and exported the tenant directory through Microsoft's own interfaces. The resulting records map organisational structure — who reports to whom, which accounts are service accounts, and which hold elevated privilege, including Global Administrator names.34 Every step after the initial credential compromise would have been an authorised action performed by an identity permitted to perform it, which is why such activity is difficult to distinguish from legitimate administration.2

Monetisation

The exported datasets were advertised for sale across cybercrime forums under the "TheHatman" handle, with per-company dumps and proof samples.23 For TCS, a sample of roughly 6,000 records was attached to a listing claiming about 800,000 records in total.1 No asking price was disclosed in the public reporting.26

Loading diagram...

Threat Actor Profile

Name: Unknown. Self-identified by the forum handle "TheHatman."

Aliases: None established; the handle is the only identifier in public reporting.23

Attribution confidence and basis: No government body, vendor, or affected company has attributed the activity to a named group or individual. "TheHatman" is a self-chosen marketplace persona, not an intelligence-tracked actor.23

Motivation: Financial. The data was listed for sale; the value of a corporate directory lies in the reconnaissance it provides for follow-on social engineering, spear-phishing and targeted privilege escalation, which Hudson Rock described as the real payoff rather than the dump itself.42

Sophistication: Moderate and opportunistic as described. The campaign relied on abuse of valid credentials and native cloud tooling rather than novel exploitation; Hudson Rock characterised the scale and speed of the dumps as suggesting "a systematic, automated approach once initial access is achieved."2

Prior operations: None reliably linked. The nine-company campaign is the only activity publicly associated with the handle.

The MITRE ATT&CK mapping below describes the claimed mechanism; the techniques are drawn from the two reported access accounts and the directory-export behaviour, and the IDs were verified on attack.mitre.org.

ID Technique
T1078.004 Valid Accounts: Cloud Accounts
T1110.003 Brute Force: Password Spraying
T1621 Multi-Factor Authentication Request Generation
T1555 Credentials from Password Stores
T1087.004 Account Discovery: Cloud Account
T1069.003 Permission Groups Discovery: Cloud Groups

Technical Indicators

actor_handle: "TheHatman (self-identified forum handle)"
marketplace: "underground / darknet cybercrime forum (listing surfaced by S2W on X)"
claimed_source: "Microsoft Azure / Entra ID directory export"
claimed_initial_access:
  - "valid credentials attributed by Hudson Rock to infostealer infections"
  - "password spray and MFA-fatigue (the attacker's own claim, as cited by TCS)"
advertised_record_count_tcs: "~800,000 (actor-advertised; ~6,000-record proof sample)"
campaign_total_records: "~3.6 million across nine named enterprises"
data_categories_claimed:
  - names
  - employee IDs
  - corporate email addresses
  - job titles and departments
  - phone numbers
  - postal and office addresses
  - manager and reporting relationships
  - group memberships
  - service accounts
  - global administrator account names
file_hashes: none disclosed
ip_addresses: none disclosed
domains: none disclosed
malware_family: "not identified in public reporting (infostealer, per Hudson Rock)"
note: >
  No network IOCs, hashes, or malware samples were released publicly; the only
  reported artifacts are the forum handle and the advertised dataset. TCS states
  it found no credible evidence of a breach, and the dataset's authenticity, age
  and origin are unverified. Employee personal data is not reproduced here — only
  the categories and the actor-advertised count are reported.

TCS's response was a Regulation 30 intimation under the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, filed with the National Stock Exchange of India and BSE on 10 August 2026 (reference TCS/SE/72/2026-27) and signed by the Company Secretary.5 Regulation 30 requires listed Indian companies to disclose material events; TCS used it to acknowledge the alerts and to record its finding of no credible evidence of a breach, rather than to report a confirmed incident.5

No enforcement or confirmatory action by an Indian authority has been located. As of 6 October 2026, the Indian Computer Emergency Response Team (CERT-In) had published no advisory, vulnerability note, or incident note referencing this campaign or TCS.7 TCS's exchange-filing history shows no further disclosure on the matter after the 10 August 2026 intimation, through 6 October 2026.8 Other named companies responded individually to journalists — Gap Inc., for example, said its data was "limited in scope, non-sensitive" with "no evidence to suggest that our corporate systems have been compromised" — but no coordinated regulatory response has been reported.6 Microsoft was approached by reporters; no platform vulnerability was identified and no Microsoft statement was published in the reporting reviewed.3

Impact Assessment

  • Confirmed: TCS received threat-intelligence alerts and formally disclosed them, stating it found no credible evidence of a breach of its systems or customer environments and no indication of impact to customer data, customer systems, or operational systems.5
  • Reported, not independently confirmed: A forum actor advertised roughly 800,000 TCS employee-directory records as part of a ~3.6 million-record campaign; Hudson Rock assessed samples "highly likely authentic."231
  • Reported (other targets): Gap Inc. and other named firms issued qualified statements; Gap said the data was limited, non-sensitive and years old.6
  • Estimated: The ~800,000 figure is the actor's own, evidenced publicly only by a ~6,000-record sample; whether the full set exists, is genuine, or is current is not established.16
  • Unknown: Whether any genuine TCS data was exfiltrated from TCS systems at all; the data's true age and provenance; the asking price (none disclosed); and whether any buyer acquired the data.52

Lessons and Defensive Recommendations

For SOC and detection teams. Treat bulk directory enumeration and export in Entra ID as a monitored event: alert on large Microsoft Graph/directory read operations, unusual service-principal or Global Administrator activity, and sign-ins exhibiting impossible travel or atypical client behaviour. The claimed vectors — password spraying and MFA-fatigue prompt bombing — are detectable through failed-authentication baselining and repeated MFA-challenge telemetry.52

For identity and cloud teams. Deploy phishing-resistant, number-matching MFA to defeat fatigue attacks; disable legacy authentication; enforce Conditional Access with risk-based controls; and apply least privilege to service accounts and app registrations so a single compromised identity cannot export the whole directory. Monitor for credentials appearing in infostealer logs, since the broader campaign was attributed to infostealer-harvested credentials used from unmanaged endpoints.23

For leadership and communications. A corporate directory is reconnaissance-grade data even when it contains no secrets: reporting relationships, service accounts and admin names are a ready map for spear-phishing and privilege escalation.4 Distinguish clearly, in any disclosure, between a breach of live systems and the recirculation of old or infostealer-sourced data, and be prepared to substantiate age and provenance claims.

For researchers and journalists. Attacker-advertised counts are self-reported; a small "proof" sample assessed as authentic is not confirmation that a full dataset exists or that it came from a current breach of the named victim.26 Keep this August 2026 directory-data claim distinct from the unrelated 2025 reporting that the Scattered Spider cluster breached Marks & Spencer via third-party TCS contractor credentials.

Sources

Footnotes

  1. Outlook Business — TCS Faces Employee Data Exposure Claim; Says No Evidence Of Systems Breach — August 10, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  2. Help Net Security — Hacker claims millions of records stolen from corporate Azure tenants — August 18, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22

  3. The Register — Crook hawks millions of records allegedly plundered from corporate Azure tenants — August 17, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15

  4. SecurityWeek — Fortune 500 Companies Hit in Azure Data Theft Campaign — August 17, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7

  5. Tata Consultancy Services — Intimation under Regulation 30 of the SEBI (LODR) Regulations, 2015 (TCS/SE/72/2026-27) — August 10, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13

  6. BleepingComputer — Hacker claims 3.6 million Azure account records stolen from major companies — August 17, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9

  7. CERT-In — Indian Computer Emergency Response Team (advisories index, checked for any TCS/Azure note) — accessed October 6, 2026 ↩ ↩2 ↩3

  8. BSE — Tata Consultancy Services Ltd corporate announcements history — accessed October 6, 2026 ↩ ↩2 ↩3

  9. Reuters (via Yahoo Finance) — India's TCS flags alleged exposure of some employee data, says customer data not impacted — August 10, 2026 ↩

Topics: #tcs#thehatman#azure#entra-id#infostealer#data-leak#india#s2w
Original Incident Report →

Related Research

Revolut answered a fraudulent Italian government data request and disclosed ~680 customers' KYC files and Bitcoin histories. A threat-intel firm disputes the attacker's own six-month RAT story; independent researchers found the real targeting method, an unresolved second compromised mailbox

Data BreachSocial Engineering

In mid-2025, the Narcotics Control Bureau (NCB) Cochin Zonal Unit executed Operation MELON, dismantling India's premier Level-4 darknet narcotics syndicate operating under the vendor moniker...

Darknet & Illicit Markets

A financially motivated threat actor (UNC5537) compromised Snowflake customer instances across 165+ organizations by credential stuffing against accounts lacking MFA, exfiltrating terabytes of sensitive data, and conducting mass extortion — the largest cloud data warehouse compromise to date.

Data BreachExtortion & Blackmail