SYS::ONLINE
Wasteland.
Briefs2241
Issues25
SinceFeb 2026
LIVE
▣ Breach HCLTECH-DATA-BREAC 2026-08-25

HCLTech: TheHatman Azure Tenant Data Sale

"HCLTech, one of India's largest IT services providers, has acknowledged that employee data attributed to it in a criminal forum listing may be genuine but old, while denying that its own systems were breached. In an…"

HCLTech, one of India's largest IT services providers, has acknowledged that employee data attributed to it in a criminal forum listing may be genuine but old, while denying that its own systems were breached. In an exchange filing dated 10 August 2026 and reported by Indian outlets on 11 August, the company said its initial investigation "has revealed that the aforesaid data may be limited and dated to a few years back," and that there is "no evidence of breach to the Company's systems or engagement with any of the Company's clients." The listing is one of roughly nine corporate datasets advertised by a threat actor using the alias "TheHatman," who claims to have pulled employee directories straight out of victims' Microsoft Azure tenants using compromised credentials.

What Happened

Starting 31 July 2026, TheHatman began posting a run of large internal employee directories on cybercrime forums, each advertised as "downloaded directly from Azure Tenant using compromised credentials." BleepingComputer reports the actor claims 3.64 million records in total. The Register, citing research from Hudson Rock, puts the haul across nine organizations: McDonald's, Tata Consultancy Services, Vodafone, HCL Technologies, IHG Hotels & Resorts, Kyndryl, Gap Inc., Hexaware Technologies, and Wyndham Hotels & Resorts. Help Net Security's account of the same Hudson Rock research matches that list.

The HCLTech dataset is advertised at roughly 250,000 employee records. That figure is consistent across the reporting: The Register and Help Net Security both cite about 250,000, and the Indian Express account carried by Hashnewz says "over 2,50,000" employees. HCLTech itself has never confirmed a record count, describing the exposure only as "limited."

Palo Alto Networks Unit 42, in its running threat brief on large-scale credential attacks updated 18 August, independently logs the campaign: "In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants." That is a vendor confirming the campaign exists and is being tracked, not a confirmation of any individual victim's data.

The disclosure landed hours after a near-identical statement from rival Tata Consultancy Services, whose alleged 800,000-record dump was posted in the same series. TCS told the National Stock Exchange of India it found no "credible evidence of a breach of TCS systems or customer environments," and said the data appeared to be at least four years old and limited to basic employee information. Separately, ETNow notes that HCLTech has not publicly named the hacker group or explained how the alleged exposure surfaced.

One minor discrepancy in the record: Hashnewz dates the exchange filing to Monday 10 August, ETNow to a statement issued 10 August, and Business Standard describes it as an exchange filing "late Monday night" with an 11 August dateline. The substance of the quoted statement is identical across all of them.

What Was Taken

Accounts of the data's contents are consistent and go well beyond a name-and-email list. Per the forum posts and Hudson Rock's sample review, the records include full names, employee IDs, corporate email addresses, job titles, departments, phone numbers, physical and postal addresses, office locations, reporting structures, group memberships, and service account records.

The Register adds a detail that matters more than the raw count: some records reportedly flag accounts holding Global Administrator privileges. Passwords are not said to be included, but a directory that identifies who holds tenant-level admin rights is an operational targeting list for phishing and help desk social engineering.

Hudson Rock assessed the material as "highly likely authentic," citing corporate email addresses and field structures consistent with a standard Microsoft Azure directory export. That assessment is a research firm's judgement on the sample set as a whole, and it does not resolve the age question. HCLTech says its slice is dated by several years; TCS put its own at four-plus years. Both claims are compatible with authentic data: an old directory export is still a real directory export.

Accounts genuinely differ on the central question. The actor and Hudson Rock frame this as live exfiltration from corporate Azure tenants. HCLTech and TCS say their tenants were not breached and the data is stale. No source in this set resolves that, and neither company has published evidence supporting the age claim.

Why It Matters

For an IT services firm the client-impact question dominates everything else, and HCLTech's filing is built around that distinction. The company runs infrastructure and holds data for enterprises across banking, healthcare, and technology, so a client-environment compromise would be a category of incident entirely different from a dated internal directory leak. HCLTech says it found no evidence of the former.

Defenders should not read "no systems breach" as "no exposure." Both readings of this incident carry risk. If the data is old, the identity graph it exposes is still largely current: employees stay in role for years, reporting lines persist, service accounts are notoriously long-lived, and admin assignments rarely churn. If the data is recent, at least one identity boundary failed somewhere in the chain. Either way, an attacker holding a structured Entra directory for a firm of this size gets a supply chain targeting map, and HCLTech's clients inherit part of that risk.

The clustering also matters. Nine large organizations, one actor, one platform, one claimed access method, over roughly three weeks. Whether that reflects a single reusable technique or an aggregation of separate compromises is the question worth answering, and no source in this set answers it.

The Attack Technique

TheHatman claims compromised credentials and direct download from victim Azure tenants. Beyond that, nobody has established the initial access vector.

Hudson Rock said plainly that it could not independently determine how the campaign was carried out: "While the data is highly likely authentic, it is not conclusive how this campaign is being carried out." Its listed possibilities are credentials or session tokens stolen by infostealer malware, highly successful phishing yielding administrative access, weak or absent MFA on specific tenant portals, and abuse of an over-permissioned third-party API or integration.

TCS gave the only victim-side technical detail available, telling exchanges that the attacker claimed password spraying and MFA fatigue as the vector, and adding that "the Company has had strong safeguards in place against such techniques for more than two years." HCLTech's filing offers no technique detail at all.

Unit 42 places the campaign in a broader pattern it has been tracking through 2026 alongside the June FortiBleed password spraying campaign against Fortinet devices: attackers assembling previously leaked username and password pairs, then spraying them against internet-exposed services to pivot into cloud tenants. Its framing is that identity is now the perimeter and adversaries prefer to log in rather than break in. Unit 42's specific detection advice is to audit remote access logs for successful logins occurring shortly after high-volume authentication failure events.

What Organizations Should Do

Sources: HCLTech says stolen data may be years-old after hacker’s data breac... | Threat Brief: Mitigating Large-Scale Credential Attacks (Updated Au... | Hacker claims 3.6 million Azure account records stolen from major c... | HCLTech Denies Data Breach Claims by Hacker Group, ETHRWorld | Crook hawks millions of records allegedly plundered from corporate... | Hacker claims millions of records stolen from corporate Azure tenan... | After TCS, HCLTech say no evidence of systems breach after hacking... | HCLTech denies system breach after hacker group's data exposure cla...