A cybercriminal operating under the alias "TheHatman" is attempting to sell what they claim is a database of 3.64 million employee records. The threat actor alleges these files were extracted directly from the Microsoft Azure environments of several Fortune 500 companies after gaining access using compromised credentials. The most significant data dump in the collection reportedly targets McDonald's. Posted on Sunday, this specific archive is said to contain 1.7 million internal employee records. According to the attacker's sales pitch, the stolen files hold names, employee identification numbers, email addresses, job titles, phone numbers, postal addresses, and tenant account details. Tata Consultancy Services represents the second-largest portion of the advertised data, with the hacker claiming to possess over 800,000 employee profiles. TheHatman stated the attack relied on password spraying and Multi-Factor Authentication (MFA) fatigue to bypass security measures. Following an internal investigation, Tata filed a notification with the National Stock Exchange of India stating there is no credible evidence that its systems or customer environments were breached. The company noted that the exposed details consist of basic employee information dating back at least four years. Tata also clarified that strict safeguards against MFA fatigue and password spraying have been in place for more than two years, and a recent review confirmed they remain effective. Clothing retailer Gap Inc. echoed similar sentiments when responding to the claims. A company spokesperson told BleepingComputer that their corporate systems remain secure and untouched. The representative characterized the data in question as limited in scope, non-sensitive, and several years old. To entice buyers, TheHatman provided sample databases for verification. Cybercrime intelligence firm Hudson Rock analyzed these samples and expressed high confidence in their authenticity. The firm confirmed the data features foundational corporate directory attributes and structured fields, including active domains and specific ".onmicrosoft.com" tenant configurations. Hudson Rock warned that the dumps include service accounts and the names of global administrators, information that malicious actors could use to launch targeted social engineering or spearphishing campaigns. Despite this confirmation of the data's structure, the actual method of access and data exfiltration remain unknown, and BleepingComputer could not independently verify the full database. This alleged breach surfaces alongside broader industry observations regarding enterprise security. For context on the scale of such threat assessments, The Blue Report 2026 recently measured defense capabilities technique by technique across 338 million simulations run in customer production environments. Somali technology professionals managing Azure environments for international businesses must monitor their administrative accounts closely. Even if the stolen directory information is outdated, these email lists and naming conventions give attackers the exact corporate structures they need to target network administrators in East Africa with highly convincing phishing attempts.