HCLTech, one of India's largest IT services providers, has acknowledged that employee data attributed to it in a criminal forum listing may be genuine but old, while denying that its own systems were breached. In an exchange filing dated 10 August 2026 and reported by Indian outlets on 11 August, the company said its initial investigation "has revealed that the aforesaid data may be limited and dated to a few years back," and that there is "no evidence of breach to the Company's systems or engagement with any of the Company's clients." The listing is one of roughly nine corporate datasets advertised by a threat actor using the alias "TheHatman," who claims to have pulled employee directories straight out of victims' Microsoft Azure tenants using compromised credentials.
What Happened
Starting 31 July 2026, TheHatman began posting a run of large internal employee directories on cybercrime forums, each advertised as "downloaded directly from Azure Tenant using compromised credentials." BleepingComputer reports the actor claims 3.64 million records in total. The Register, citing research from Hudson Rock, puts the haul across nine organizations: McDonald's, Tata Consultancy Services, Vodafone, HCL Technologies, IHG Hotels & Resorts, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels & Resorts. Help Net Security's account of the same Hudson Rock research matches that list.
The HCLTech dataset is advertised at roughly 250,000 employee records. That figure is consistent across the reporting: The Register and Help Net Security both cite about 250,000, and the Indian Express account carried by Hashnewz says "over 2,50,000" employees. HCLTech itself has never confirmed a record count, describing the exposure only as "limited."
Palo Alto Networks Unit 42, in its running threat brief on large-scale credential attacks updated 18 August, independently logs the campaign: "In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants." That is a vendor confirming the campaign exists and is being tracked, not a confirmation of any individual victim's data.
The disclosure landed hours after a near-identical statement from rival Tata Consultancy Services, whose alleged 800,000-record dump was posted in the same series. TCS told the National Stock Exchange of India it found no "credible evidence of a breach of TCS systems or customer environments," and said the data appeared to be at least four years old and limited to basic employee information. Separately, ETNow notes that HCLTech has not publicly named the hacker group or explained how the alleged exposure surfaced.
One minor discrepancy in the record: Hashnewz dates the exchange filing to Monday 10 August, ETNow to a statement issued 10 August, and Business Standard describes it as an exchange filing "late Monday night" with an 11 August dateline. The substance of the quoted statement is identical across all of them.
What Was Taken
Accounts of the data's contents are consistent and go well beyond a name-and-email list. Per the forum posts and Hudson Rock's sample review, the records include full names, employee IDs, corporate email addresses, job titles, departments, phone numbers, physical and postal addresses, office locations, reporting structures, group memberships, and service account records.
The Register adds a detail that matters more than the raw count: some records reportedly flag accounts holding Global Administrator privileges. Passwords are not said to be included, but a directory that identifies who holds tenant-level admin rights is an operational targeting list for phishing and help desk social engineering.
Hudson Rock assessed the material as "highly likely authentic," citing corporate email addresses and field structures consistent with a standard Microsoft Azure directory export. That assessment is a research firm's judgement on the sample set as a whole, and it does not resolve the age question. HCLTech says its slice is dated by several years; TCS put its own at four-plus years. Both claims are compatible with authentic data: an old directory export is still a real directory export.
Accounts genuinely differ on the central question. The actor and Hudson Rock frame this as live exfiltration from corporate Azure tenants. HCLTech and TCS say their tenants were not breached and the data is stale. No source in this set resolves that, and neither company has published evidence supporting the age claim.
Why It Matters
For an IT services firm the client-impact question dominates everything else, and HCLTech's filing is built around that distinction. The company runs infrastructure and holds data for enterprises across banking, healthcare, and technology, so a client-environment compromise would be a category of incident entirely different from a dated internal directory leak. HCLTech says it found no evidence of the former.
Defenders should not read "no systems breach" as "no exposure." Both readings of this incident carry risk. If the data is old, the identity graph it exposes is still largely current: employees stay in role for years, reporting lines persist, service accounts are notoriously long-lived, and admin assignments rarely churn. If the data is recent, at least one identity boundary failed somewhere in the chain. Either way, an attacker holding a structured Entra directory for a firm of this size gets a supply chain targeting map, and HCLTech's clients inherit part of that risk.
The clustering also matters. Nine large organizations, one actor, one platform, one claimed access method, over roughly three weeks. Whether that reflects a single reusable technique or an aggregation of separate compromises is the question worth answering, and no source in this set answers it.
The Attack Technique
TheHatman claims compromised credentials and direct download from victim Azure tenants. Beyond that, nobody has established the initial access vector.
Hudson Rock said plainly that it could not independently determine how the campaign was carried out: "While the data is highly likely authentic, it is not conclusive how this campaign is being carried out." Its listed possibilities are credentials or session tokens stolen by infostealer malware, highly successful phishing yielding administrative access, weak or absent MFA on specific tenant portals, and abuse of an over-permissioned third-party API or integration.
TCS gave the only victim-side technical detail available, telling exchanges that the attacker claimed password spraying and MFA fatigue as the vector, and adding that "the Company has had strong safeguards in place against such techniques for more than two years." HCLTech's filing offers no technique detail at all.
Unit 42 places the campaign in a broader pattern it has been tracking through 2026 alongside the June FortiBleed password spraying campaign against Fortinet devices: attackers assembling previously leaked username and password pairs, then spraying them against internet-exposed services to pivot into cloud tenants. Its framing is that identity is now the perimeter and adversaries prefer to log in rather than break in. Unit 42's specific detection advice is to audit remote access logs for successful logins occurring shortly after high-volume authentication failure events.
What Organizations Should Do
- Hunt for the spray-then-succeed pattern in Entra ID sign-in logs. Per Unit 42, look for a successful authentication closely following a burst of failures for the same account or from the same source, and extend the lookback across the full window from late July onward rather than the last few days.
- Audit directory read access, not just admin access. This data is a directory export. Review which users, service principals, and third-party enterprise applications hold Directory.Read.All or equivalent Graph permissions, revoke what is not justified, and check consent grants for apps nobody remembers approving.
- Treat MFA fatigue as an unclosed gap unless you have specifically closed it. Number matching, per-application conditional access, and phishing-resistant factors for privileged roles defeat push bombing; plain push approval does not.
- Inventory and lock down service accounts. They appear in the advertised records, they typically lack MFA, and they are the most likely path from a stale credential to a live tenant.
- Assume Global Administrator identities are now on a targeting list. Enforce privileged identity management with just-in-time elevation, separate admin identities from daily-driver accounts, and brief those users that they are named phishing targets.
- Harden the help desk against identity-based social engineering. A directory containing manager names, employee IDs, phone numbers, and office locations is exactly what an attacker needs to pass a verbal identity check and request an MFA reset.
- For clients of large IT service providers, ask directly. Request written confirmation on whether provider-side identities with access to your environment were included in any exposed dataset, and rotate credentials for delegated administrative access as a precaution.
Sources: HCLTech says stolen data may be years-old after hacker’s data breac... | Threat Brief: Mitigating Large-Scale Credential Attacks (Updated Au... | Hacker claims 3.6 million Azure account records stolen from major c... | HCLTech Denies Data Breach Claims by Hacker Group, ETHRWorld | Crook hawks millions of records allegedly plundered from corporate... | Hacker claims millions of records stolen from corporate Azure tenan... | After TCS, HCLTech say no evidence of systems breach after hacking... | HCLTech denies system breach after hacker group's data exposure cla...